aiR for Data Breach Response

When a data breach occurs, one of the first questions organisations need answered is who has been affected? Finding that answer can be difficult when exposed data is unstructured, duplicated across systems and mixed across emails, documents, spreadsheets, and other files. 

aiR for Data Breach Response helps identify Personal Information (PII) and Personal Health Information (PHI) across large volumes of data and links that information to the people or organisations it belongs to. Instead of manually reviewing data for weeks, teams can generate a consolidated list of potentially impacted individuals in days. 

At Law In Order, we help organisations use RelativityOne’s AI capabilities to respond to data breaches more quickly, accurately and defensibly. 

How aiR for Data Breach Response works

aiR for Data Breach Response is designed to analyse both unstructured and structured data, allowing organisations to quickly understand what information has been exposed and who may be impacted. 

Unstructured data analysis

Emails, documents, and other unstructured files are analysed using document context to identify personal and health information contained within the material.

Structured data analysis

Spreadsheets and tabular data are assessed by identifying table boundaries, column headers and values, enabling accurate extraction of relevant information.

Optical character recognition (OCR)

Scanned documents and image-based files are processed using OCR before analysis, ensuring that information contained in scanned material is also captured.

The platform identifies, extracts and links relevant information to the appropriate individual or organisation, creating a consolidated view of potentially impacted people. 

Built into RelativityOne

aiR for Data Breach Response is part of the Relativity aiR suite of generative AI tools built into RelativityOne, alongside aiR Assist, aiR for Review, aiR for Privilege and aiR for Case Strategy. 

Because it operates within the same RelativityOne environment, organisations benefit from a consistent security model, audit trail and governance framework across eDiscovery, investigations and breach response. 

Enterprise-scale breach analysis

The platform is designed for large-scale breach response matters and can support: 
  • Up to 300 million personal information annotations 
  • Up to 150 million entities 
  • Approximately 1 terabyte of native data per workspace 

Larger collections can be processed increments against that quota. Embedded documents and very large native files fall outside the supported range. 

Personal information detectors

aiR for Data Breach Response includes a library of detectors for common personal, financial, contact and health information. Detectors can be enabled or disabled on a per-matter basis so that analysis is limited to information relevant to the incident. 

Built-in detectors

Common detectors include identifiers such as:
Australian Tax File Number (TFN)
Individual Healthcare Identifier (IHI)
Medicare Provider Number

Custom detectors

Additional detectors can be created and validated for Australian and New Zealand identifiers, including:
ABN
ACN
BSB
Australian driver licence numbers
IRD numbers
NZBN

Custom detectors use regular expressions combined with keyword and exclusion rules to improve accuracy and reduce false positives.

The questions aiR helps answer

During a breach response, organisations need clear and defensible answers. aiR for Data Breach Response helps answer questions such as: 

  • What personal information was exposed? 
  • Which individuals are affected? 
  • What information is held about each individual? 
  • Is confidential or sensitive material involved? 
  • What can we report to regulators, insurers and stakeholders? 

Why choose Law In Order

Law In Order combines RelativityOne expertise with practical experience managing complex data matters across legal, corporate and government environments. 

Configure and validate personal information detectors

Process and analyse breach data in RelativityOne

Identify affected individuals and organisations

Prepare defensible reporting for regulators, insurers and stakeholders

Integrate breach response workflows with broader eDiscovery and investigation processes

Explore the aiR Suite

aiR Assist

Understand your data before review begins.

aiR for Review

Assess documents at scale.

aiR for Privilege

Support privilege identification and review.

aiR for Case Strategy

Build a stronger understanding of the facts.

FAQ aiR for Data Breach Response

It can help organisations analyse large data sets and generate a consolidated view of potentially affected individuals in days rather than relying solely on manual review.

It can analyse emails, documents, spreadsheets, scanned documents and other structured and unstructured data.

Yes. Built-in and custom detectors can support identifiers relevant to Australian and New Zealand matters, including TFNs, ABNs, ACNs and IRD numbers.

Yes. Custom detectors can be configured for information specific to the breach or jurisdiction, using defined detection rules.

Yes. OCR can be used to process image-based and scanned documents so relevant information can be identified.

It identifies relevant personal information within the data and links detected information to the associated individual or organisation.

It can help establish what information was exposed and who may be affected, providing information that can support reporting to regulators, insurers and other stakeholders.

Yes. The platform is designed to support enterprise-scale breach analysis, including matters involving very large volumes of personal information.

Yes. Law In Order can assist with configuring detectors, analysing breach data, identifying potentially affected individuals and supporting defensible reporting.

Yes. It operates within RelativityOne and can form part of broader eDiscovery, investigation and information governance workflows.

Talk to our team

If your organisation is responding to a data breach or preparing for future breach response requirements, our team can help you assess how aiR for Data Breach Response can support a faster, more accurate and defensible response.