Control Sophos Central privacy and data sharing
Sophos Central can transfer telemetry, logs, and suspicious files to Sophos services. This improves detection, Threat Graphs, and troubleshooting, but may involve personal, confidential, or regulated data. A green Health Check score therefore cannot replace a substantive privacy decision.
Tenant-wide options are under Profile > Account preferences > Privacy. Product-specific sharing can also exist in policies, Global Settings, or an Early Access Program.
Understand the Compliance area
The Compliance area helps administrators assess compliance with required security standards. It is a technical control and reporting aid, not an automatic certification or a substitute for an organization’s own risk, legal, or audit assessment. Before using it, define the required standard, the actually licensed product scope, data currency, deviations, and responsible evidence owners.
A green or complete status proves only the controls assessed by Sophos Central. Organizational measures, systems outside the tenant, and exclusions not captured by Central remain part of the organization’s compliance process. Track deviations with an owner, deadline, and technical evidence.
Assess each sharing option separately
| Option | Purpose | Potential data involved |
|---|---|---|
| Send Threat Graph data to Sophos | Analyze causal chains and relationships around a detection | Process, file, user, and event data |
| Send Intercept X data to Sophos | Improve protection and classification | Security and device telemetry |
| Send Data to Generative AI Tools for US Data Processing | Enable generative AI functions with processing in the US | Content submitted to an AI function |
| Send logs and related files to Sophos when the device is unhealthy | Simplify automatic troubleshooting and support | Logs may contain personal and internal data |
| Submit sample files to Sophos automatically | Analyze unknown or suspicious objects | Files may contain email, URL, or business content |
Do not enable all options as one package. For each sharing option, document its purpose, legal basis or internal approval, affected systems, data region, retention, and responsible party.
Understand Sample Submission
Sample Submission sends a copy when a file appears suspicious from its characteristics, Sophos cannot classify it conclusively, and no sample is already available. Sophos recommends the function to improve detection and reduce false positives.
A sample can include not only an executable file, but also email or URL content. The maximum sample size is 10 MB and the upload timeout is 30 seconds. These limits do not make smaller files harmless. Source code, contracts, medical data, or credentials remain sensitive regardless of file size.
Disabling automatic submission reduces cloud analysis available for previously unknown objects. Security, privacy, and business owners should decide this trade-off together rather than leaving it to one endpoint administrator.
Send released quarantine emails to SophosLabs
Sophos Email also has the Account Preference Send data from released quarantined emails to SophosLabs. When enabled, Sophos transmits information or samples from emails released from quarantine by an administrator or user. Sophos uses them for analysis and to improve detection accuracy.
A quarantine release can involve business content, sender, recipient, and other message data. Document this as a separate Sophos Email data-sharing decision rather than deriving it silently from the general Sample Submission decision. After a change, jointly review the quarantine workflow, ownership, privacy approval, and expected transfer.
Logs from unhealthy devices
Sharing logs and related files can shorten diagnosis because Sophos automatically receives technical data from an unhealthy device. Logs may, however, contain usernames, paths, hostnames, IP addresses, URLs, or application information.
Before enabling it, identify device types that process particularly sensitive data. In highly regulated environments, a controlled, case-specific upload after review may be more appropriate than general automatic transmission.
Approve generative AI separately
The generative AI option explicitly identifies processing in the United States. Do not enable it for convenience together with conventional security telemetry. First define contractual requirements, data classification, permitted prompts, and handling of incident data.
Users must not paste secrets, complete customer datasets, or unredacted logs into AI fields. Even with the tenant option enabled, the administrator remains responsible for the specific content.
Intelix Service Region
Account Preferences lets administrators select the region to which endpoints and servers send files when a SophosLabs Intelligence analysis is requested. Align this setting with the documented Central data region and internal requirements.
The Intelix region is not automatically identical to the data region of every other Central function. Privacy documentation should therefore describe the individual services rather than a single blanket storage location.
Account Health and Auto-Fix
The Protection improvement check can flag missing sharing for Threat Graph data, Intercept X data, and malware samples. Fix automatically can turn this into a tenant-wide change.
After every change, verify the Audit Log, Account Health, affected functions, and expected data flow. Reassess the decision at least annually and whenever licenses, AI functions, regions, or regulatory requirements change. Technical controls are described in Analyze and retain Sophos Central Audit Logs and Use Sophos Central Account Health Check correctly.