Device IMEI numbers
Identifies documents containing references to device imei numbers in Australian contexts. This information type is classified as personally identifiable information under applicable data protection regulations. Detection is phrase-level concept matching anchored on explicit IMEI, TAC, and equipment-identity vocabulary; it does not parse or Luhn-validate 15-digit IMEI values.
- Type
- regex
- Engine
- boost_regex
- Confidence
- medium
- Confidence justification
- category-aware structural regex with anchor and context constraints replaces phrase-only detection. Added context gating and exclusion rules improve precision and reduce incidental matches.
- Detection quality
- Topic false positive
- Jurisdictions
- global
- Regulations
- SOCI Act 2018 (Cth), TIA Act 1979 (Cth), GDPR
- Frameworks
- CIS Controls, DISP, ISO 27001, NIST CSF, SOC 2
- Data categories
- pii
- Scope
- wide
- Risk rating
- 5
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported
Pattern
(?is)\b(?:device\s+IMEI\s+numbers|IMEI\s+number|handset\s+identifier|type\s+allocation\s+code|equipment\s+identity)\b
Corroborative evidence keywords
device imei numbers, device, imei, numbers, contact, location, data, fax, facsimile, toll free, hotline, helpline, [object Object], [object Object], country code, area code, extension, ext, data record, database record (+22 more)
Proximity: 300 characters
Should match
device IMEI numbers— Primary topic phrase matchimei number— Case-insensitive topic phrase matchequipment identity— Alternative topic phrase matchtype allocation code— Additional topic phrase match
Should not match
unrelated generic text without domain phrases— No relevant topic phrases presentplaceholder value 12345— Random text should not match topic-specific regexaddress mac— Generic word pair from old broad template should not matchMobile device management policy— Generic mobile-device wording demoted out of the primary - MDM policy prose must not anchor the SITasset serial number register— Generic serial-number wording demoted out of the primary - asset inventories must not anchor the SIT
Known false positives
- Common words and phrases related to device imei numbers appearing in policy documents, training materials, HR templates, or compliance guidelines without actual personal data. Mitigation: Require corroborative evidence keywords within the proximity window to confirm sensitive data context rather than general discussion.
- In Australian English, similar terminology used in formal or administrative contexts (education, professional documentation) that does not constitute sensitive data collection. Mitigation: Layer with additional contextual signals such as structured identifiers, form fields, or database column headers to distinguish sensitive records from general references.
- High-frequency pattern matches in large document corpora due to broad regex anchors. Expected match rate is significantly higher than specific identifier patterns. Mitigation: Tune confidence thresholds for bulk scanning. Consider using this pattern primarily as a pre-filter with secondary validation.
References
- https://www.oaic.gov.au/privacy/your-privacy-rights/your-personal-information/what-is-personal-information
- https://www.oaic.gov.au/privacy/your-privacy-rights/your-personal-information/what-is-sensitive-information
- https://www.oaic.gov.au/privacy/australian-privacy-principles-guidelines
- https://www.service.nsw.gov.au/transaction/check-a-vehicle-registration
- https://www.gsma.com/get-involved/working-groups/terminal-steering-group/imei-database/
- https://www.itu.int/rec/T-REC-E.118.1/en