Abstract. Privacy violations and the exposition of sensitive data to a third party may seriously damage the business of a company. Therefore, it is crucial for the company to identify that set of users that may have exposed the sensitive data. To identify that set of users is a problem, when multiple users must have access rights that allow them to access the exposed sensitive data. Our solution to the problem is based on an analysis of the users' XPath queries. Within a two-step approach, we compare submitted queries with the exposed data to identify suspicious queries.