Control Sophos Fusion privacy and data sharing
Sophos Fusion (formerly Sophos Central) can transfer telemetry, logs, and suspicious files to Sophos services. This improves detection, Threat Graphs, and troubleshooting, but may involve personal, confidential, or regulated data. A green Health Check score therefore cannot replace a substantive privacy decision.
Tenant-wide options are under Profile > Account preferences > Privacy. Product-specific sharing can also exist in policies, Global Settings, or an Early Access Program.
Understand the Compliance area
The Compliance area helps administrators assess compliance with required security standards. It is a technical control and reporting aid, not an automatic certification or a substitute for an organization’s own risk, legal, or audit assessment. Before using it, define the required standard, the actually licensed product scope, data currency, deviations, and responsible evidence owners.
A green or complete status proves only the controls assessed by Sophos Fusion. Organizational measures, systems outside the tenant, and exclusions not captured by Fusion remain part of the organization’s compliance process. Track deviations with an owner, deadline, and technical evidence.
Use Sophos update integrity as scoped evidence
Sophos describes several layers of integrity checking for its software updates: Sophos digitally signs binary files, devices download the files over a secure HTTPS session, and they retrieve a Sophos-signed manifest listing the files to install. A device installs only files that appear in the manifest and are signed by Sophos.
This provides technical evidence of the origin and integrity of an approved update package. It does not prove that every device is up to date or that the tenant as a whole is compliant. An audit should therefore also record update status, failed installations, exceptions, and the assessment date.
Understand the scope of Legal Notices
Sophos Legal Notices cover copyright and trademarks in the Sophos documentation. They do not describe transferred data, retention periods, or data regions and do not replace a contract, Data Processing Agreement, or the organization’s own legal review. Store compliance records and the Legal Notices as separate evidence.
Assess each sharing option separately
| Option | Purpose | Potential data involved |
|---|---|---|
| Send Threat Graph data to Sophos | Analyze causal chains and relationships around a detection | Process, file, user, and event data |
| Send Intercept X data to Sophos | Improve protection and classification | Security and device telemetry |
| Send Data to Generative AI Tools for US Data Processing | Enable generative AI functions with processing in the US | Content submitted to an AI function |
| Send logs and related files to Sophos when the device is unhealthy | Simplify automatic troubleshooting and support | Logs may contain personal and internal data |
| Submit sample files to Sophos automatically | Analyze unknown or suspicious objects | Files may contain email, URL, or business content |
Do not enable all options as one package. For each sharing option, document its purpose, legal basis or internal approval, affected systems, data region, retention, and responsible party.
Understand Sample Submission
Sample Submission sends a copy when a file appears suspicious from its characteristics, Sophos cannot classify it conclusively, and no sample is already available. Sophos recommends the function to improve detection and reduce false positives.
A sample can include not only an executable file, but also email or URL content. The maximum sample size is 10 MB and the upload timeout is 30 seconds. These limits do not make smaller files harmless. Source code, contracts, medical data, or credentials remain sensitive regardless of file size.
Disabling automatic submission reduces cloud analysis available for previously unknown objects. Security, privacy, and business owners should decide this trade-off together rather than leaving it to one endpoint administrator.
Send released quarantine emails to SophosLabs
Sophos Email also has the Account Preference Send data from released quarantined emails to SophosLabs. When enabled, Sophos transmits information or samples from emails released from quarantine by an administrator or user. Sophos uses them for analysis and to improve detection accuracy.
A quarantine release can involve business content, sender, recipient, and other message data. Document this as a separate Sophos Email data-sharing decision rather than deriving it silently from the general Sample Submission decision. After a change, jointly review the quarantine workflow, ownership, privacy approval, and expected transfer.
Logs from unhealthy devices
Sharing logs and related files can shorten diagnosis because Sophos automatically receives technical data from a device with the status unhealthy. Logs may, however, contain usernames, paths, hostnames, IP addresses, URLs, or application information.
Before enabling it, identify device types that process particularly sensitive data. In highly regulated environments, a controlled, case-specific upload after review may be more appropriate than general automatic transmission.
Approve generative AI separately
The generative AI option explicitly identifies processing in the United States. Do not enable it for convenience together with conventional security telemetry. First define contractual requirements, data classification, permitted prompts, and handling of incident data.
Users must not paste secrets, complete customer datasets, or unredacted logs into AI fields. Even with the tenant option enabled, the administrator remains responsible for the specific content.
Intelix Service Region
Account Preferences lets administrators select the region to which endpoints and servers send files when a SophosLabs Intelligence analysis is requested. Align this setting with the documented Fusion data region and internal requirements.
The Intelix region is not automatically identical to the data region of every other Fusion function. Privacy documentation should therefore describe the individual services rather than a single blanket storage location.
Document DNS Protection data processing
DNS Protection processes DNS query data to apply customer-specific filtering policies, report risky activity, examine historical DNS activity for anomalies, and troubleshoot errors. Sophos also uses the data to develop the product and its performance, including advanced detection and security techniques. Sophos Engineering analyzes telemetry to plan the roadmap and develop the product. Sophos Labs or Sophos AI may access data for analysis, threat detection, research, and continuous improvement.
The data processed includes the public IP address from which the query originates, the requested domain, tenant ID, time, and DNS response. The username and endpoint device name are processed only when Endpoint DNS Protection is used. The service also processes system events and software logs.
According to Sophos, permanent processing and storage take place in AWS data centers in the region selected when the Sophos Central account was created. However, DNS queries are automatically routed to a suitable AWS Point of Presence for the requesting device or network. This Point of Presence may be outside the selected Central region. Data collected there is stored only temporarily before being forwarded to the selected Central region. This distinction between the transport path and the permanent storage region must be stated explicitly in the privacy assessment.
DNS Protection data made available to customers in Sophos Central is retained for 90 days, while diagnostic logs are retained for 30 days. According to the data sheet, configuration data is retained for as long as the service is required. The review must therefore document at least the data types, processing purposes, selected Central region, possible Point of Presence route, retention periods, and subprocessors used by Sophos. The data sheet substantiates the information about data types, regions, and retention periods. Customer approval must be documented separately.
To verify this, open Sophos Central > Logs & Reports and check whether DNS query data for the expected period is visible and assigned to the correct tenant. If expected entries are missing, or questions remain about the region, retention, or subprocessors, do not infer approval from the data sheet. Clarify the matter with the privacy owners or Sophos. Setup, policies, and operational troubleshooting remain in the primary Sophos DNS Protection guide.
Account Health and Auto-Fix
The Protection improvement check can flag missing sharing for Threat Graph data, Intercept X data, and malware samples. Fix automatically can turn this into a tenant-wide change.
After every change, verify the Audit Log, Account Health, affected functions, and expected data flow. Reassess the decision at least annually and whenever licenses, AI functions, regions, or regulatory requirements change. Technical controls are described in Analyze and retain Sophos Fusion Audit Logs and Use Sophos Fusion Account Health Check correctly.