Skip to main content

Making Sensitivity Labels Actionable in eDiscovery Review

Why Sensitivity Labels Matter More Than Ever

As organizations strengthen their information governance and security programs, sensitivity labels have become a foundational control. Microsoft Information Protection (MIP) sensitivity labels allow organizations to classify documents and communications based on risk, confidentiality, and regulatory requirements. These labels drive downstream controls such as encryption, access restrictions, data loss prevention, and auditability across Microsoft 365 and beyond.

In the context of eDiscovery, however, the value of sensitivity labels hinges on one critical question:

Can reviewers actually see and rely on them during review?

The Hidden Challenge: Sensitivity Labels Are Not Always Human-Readable

A common misconception is that sensitivity labels are stored as clean, user-friendly values such as “Confidential” or “Legal Privilege.” In practice, that is often not the case.

When data is processed outside of its native Microsoft 365 tenant, such as through industry standard eDiscovery processing tools, sensitivity label information is typically extracted as technical metadata, not human-readable labels.

For example:

  • Some labels are stored as a GUID, rather than a descriptive name.
  • Email messages often embed label information inside a single composite metadata field containing multiple key-value pairs, such as label IDs, timestamps, and encryption indicators.
  • The same label may be represented differently depending on whether it was applied to a document or an email.

As a result, the extracted values are frequently not suitable for reviewers to interpret or rely upon within Relativity.

KPMG Approach: Translating Technical Labels into Review-Ready Metadata

Recognizing this gap, KPMG developed a proprietary approach to bridge the divide between how sensitivity labels are stored technically and how they need to be presented for legal review.

A core design principle was flexibility. Organizations routinely create custom sensitivity labels to reflect their unique risk profiles, regulatory obligations, and business requirements. A one-size-fits-all approach would quickly become obsolete.

To address this, our solution incorporates a customizable mapping layer that allows organizations to:

  • Map internal or tenant-specific- label identifiers to plain English- review values.
  • Extend or update mappings as new labels are introduced.
  • Normalize multiple technical representations of the same label into a single, consistent review value.

At a high level, the workflow includes:

  • Reading sensitivity label values directly from delivery load files.
  • Parsing technical label metadata, including composite fields that may contain multiple label artifacts.
  • Extracting only the relevant label signals while discarding non-review-relevant technical noise.
  • Generating a Relativity-ready overlay so labels appear as clean, defensible metadata fields.

This approach allows sensitivity labels to function like any other trusted review field; searchable, filterable, and auditable.

Forensic Technology

KPMG eDiscovery/Evidence & Discovery Management services help make the discovery process more cost-effective.

Meet our team

Image of David Nides
David Nides
Principal, Advisory, KPMG US
Image of Steve Lutkus
Steve Lutkus
Director Advisory, Forensic, KPMG US

Thank you!

Thank you for contacting KPMG. We will respond to you as soon as possible.

Contact KPMG

Use this form to submit general inquiries to KPMG. We will respond to you as soon as possible.
All fields with an asterisk (*) are required.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services KPMG can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the KPMG International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline