| CPC G06F 21/6245 (2013.01) [H04L 63/20 (2013.01); H04W 12/02 (2013.01); H04W 12/08 (2013.01); H04W 88/02 (2013.01)] | 14 Claims | 

| 
               1. A method comprising: 
            identifying, by a policy management module on a client computing device, personal data associated with the client computing device; 
                receiving, by the policy management module, from a server, an analysis associated with the client computing device, wherein the analysis is generated by: 
                creating, by the server, a set of fake personal data; 
                  transmitting, by the server, the fake personal data to the client computing device; 
                  tracking, by the server, access of the fake personal data by an application installed on the client computing device; and 
                  identifying, by the server, the application that accessed the fake personal data; 
                creating, by the policy management module, a policy to disallow access of the personal data by the identified application; 
                assigning the created policy to the client computing device; and, 
                generating a report by the server to alert a user of the client computing device, the alert including access of fake personal data by the application. 
               |