How to use data classification in Dropbox Protect

Admins Updated Oct 02, 2026

In this article

person icon

The information in this article applies to Dropbox Protect admins in the United States.

Data classification is the process of scanning your items for the specific sensitive data types listed below, and organizing them into categories. Data classification is disabled by default and must be enabled to scan eligible items. To enable Data classification, contact your account manager. 

Data classification uses Data categories and Data types to show whether personally identifiable information (PII) or payment card information (PCI) is detected in an item. 

  • Data category: Which group the sensitive information belongs in, PII or PCI
  • Data type: What type of sensitive information is detected

Identifying these details and using the Data category and Data type filters can help you find sensitive files, investigate potential risks, and prioritize fixes. Learn more about filtering in Protect. 

When Data classification is enabled, it can also be used to calculate Risk. Learn more about Risk categorization. 

highlighter icon

Note: Data classification uses regex (regular expressions) and keywords to find sensitive information in your files. Even when Protect identifies a match with high confidence, the result may not be 100% accurate.

Dropbox Protect doesn’t store the information in your files. It only uses the information to apply the classification labels.

Types of PII and PCI Protect can identify

Data types are organized into Data categories, PII and PCI. Some data types can be found in multiple categories.

Type

PII

PCI

Credit card numbers

✓ 

✓ 

US bank account numbers

✓ 

 

International Bank Account Numbers (IBANs)

✓ 

 

Person names

✓ 

 

US bank routing numbers

✓ 

 

US driver’s license numbers

✓ 

 

US Individual Taxpayer Identification Numbers (ITINs)

✓ 

 

US passport numbers

✓ 

 

US Social Security numbers

✓ 

 

highlighter icon

Note: Data categories and data types show that an item may contain sensitive information. You’ll still need to determine whether the way this data is used meets your organization’s legal, regulatory, or compliance requirements. 

File requirements for Protect to scan for PII and PCI

To scan files for PII and PCI, the file must be 25 MB or smaller, not password protected, and use one of the following file types:

  • CSV and JSON
  • Excel files: .xls and .xlsx
  • Google Docs, Google Sheets, and Google Slides
  • PDF
  • PowerPoint files: .ppt, .pptm, and .pptx
  • RTF
  • Text files: .txt
  • Word documents: .doc and .docx
highlighter icon

Note: Data classification can’t scan password-protected files. However, you can still apply fixes to other security risks.

Data classification details

While you are viewing the “Items” page you will see columns for Data category and Data Type.

In the item detail drawer, you can view more information about the Data classification by clicking the #Data classification section.

  • Category
  • Type
  • Total matches 
  • Confidence
    • High: Protect found stronger evidence that the content matches the data type, such as a matching pattern, a recognized format, and relevant context.
    • Medium: Protect found evidence that supports a match but with less certainty than a high-confidence detection.

Confidence indicates how certain Protect is that a match contains sensitive data. If there are different confidence levels for a Data type, they will be listed side by side with the number of matches per level. 

Was this article helpful?

Let us know how why it didn't help:

Thanks for letting us know!

Thanks for your feedback!

Footer-Help