A starting point, not a compliance guarantee. These mappings are exactly the sensitive information types Microsoft
bundles into each built-in DLP policy template — the defensible answer to "which SITs relate to this regulation." But a
real policy is more than a SIT list: templates combine SITs with boolean logic, instance counts, and location scope,
and the Enhanced variants also layer in trainable classifiers and large keyword lists
(e.g. HIPAA requires an identity SIT AND a medical-terms match). Detecting these SITs does not by itself establish
regulatory compliance. Always confirm against the
full template definitions.
No regulations match your filters.