0% found this document useful (0 votes)
5 views9 pages

Data Mapping Overview

Data mapping is essential for GDPR compliance, helping organizations document the lifecycle of personal data from collection to deletion. It involves identifying personal data categories, data subjects, lawful bases, systems, and security controls, while also facilitating accountability and risk assessments. The document provides a step-by-step guide for effective data mapping, including stakeholder interviews and documentation of data flows.

Uploaded by

macraaiclass
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views9 pages

Data Mapping Overview

Data mapping is essential for GDPR compliance, helping organizations document the lifecycle of personal data from collection to deletion. It involves identifying personal data categories, data subjects, lawful bases, systems, and security controls, while also facilitating accountability and risk assessments. The document provides a step-by-step guide for effective data mapping, including stakeholder interviews and documentation of data flows.

Uploaded by

macraaiclass
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Data Mapping under the GDPR – Detailed

Overview & Step-by-Step Guide


Data mapping is a foundational requirement for compliance with
the General Data Protection Regulation (GDPR). It enables
organizations to understand:

 What personal data they collect


 Why they collect it
 Where it flows
 Who has access to it
 How long they retain it
 How it is protected

Without data mapping, compliance with GDPR Articles 5, 6, 30,


32, and 35 becomes nearly impossible.

1️⃣ What is Data Mapping?


Data mapping is the process of documenting the lifecycle of
personal data within an organization — from collection to deletion.

It visually or structurally shows:


Collection → Storage → Usage → Sharing → Archiving → Deletion

2️⃣ Why Data Mapping is Critical


for GDPR
Under GDPR, organizations must demonstrate:

🔹 Accountability (Article 5(2))


You must prove compliance.

🔹 Records of Processing Activities (ROPA) – Article 30

Data mapping feeds directly into ROPA documentation.

🔹 Data Protection Impact Assessments (DPIA) – Article 35

You cannot assess risk if you don’t know where data flows.

🔹 Data Subject Rights

To respond to:

 Access requests
 Erasure requests
 Portability requests

You must know exactly where the data resides.

3️⃣ What Must Be Mapped?


Under GDPR, data mapping should identify:

A. Categories of Personal Data

 Names
 ID numbers
 Email addresses
 IP addresses
 Location data
 Financial data
 Health data (special category)

B. Data Subjects
 Customers
 Employees
 Vendors
 Website visitors

C. Lawful Basis (Article 6)

 Consent
 Contract
 Legal obligation
 Legitimate interest
 Vital interests
 Public task

D. Systems & Storage Locations

 CRM systems
 HR systems
 Email servers
 Cloud storage
 Backup systems
 Paper files

E. Data Transfers

 Third-party processors
 Cloud providers
 Cross-border transfers outside EU

F. Retention Periods

G. Security Controls

 Encryption
 Access controls
 Monitoring
 Data masking
4️⃣ Step-by-Step Data Mapping
Process

✅ Step 1: Define Scope


Determine:

 Which business units?


 Which jurisdictions?
 Which systems?

Example:

 HR Department
 Marketing Department
 Finance Department

✅ Step 2: Identify Data Collection Points


Where is personal data collected?

 Website forms
 Job applications
 Contracts
 Mobile apps
 CCTV systems
 Customer onboarding

Create a Data Inventory List.


✅ Step 3: Conduct Stakeholder Interviews
Meet with:

 IT
 HR
 Marketing
 Legal
 Security
 Operations

Ask:

 What personal data do you collect?


 Why?
 Where is it stored?
 Who accesses it?
 Is it shared externally?

✅ Step 4: Identify Data Elements


Example:

Process Data Collected Data Subject


Recruitment CV, ID number Job applicant
Payroll Bank account Employee
CRM Email, phone Customer

✅ Step 5: Document Data Flows


Map how data moves:
Website → CRM → Marketing tool → Email platform → Cloud backup
Use:

 Flow diagrams
 Swimlane diagrams
 Data flow charts

✅ Step 6: Identify Lawful Basis


For each processing activity, document:

Processing Activity Lawful Basis


Payroll Legal
obligation
Marketing emails Consent
Service delivery Contract

✅ Step 7: Identify Third-Party Processors


Document:

 Cloud providers
 Payroll vendors
 CRM providers
 IT support

Check:

 Data Processing Agreements (DPAs)


 Cross-border transfer safeguards (SCCs)

✅ Step 8: Identify International Transfers


If data leaves the EU:

 Adequacy decision?
 Standard Contractual Clauses?
 Binding Corporate Rules?

✅ Step 9: Define Retention & Deletion Rules


Example:

Data Type Retention Period


CVs 6 months
Payroll 5–7 years
records
Marketing data Until consent withdrawn

✅ Step 10: Assess Security Controls


Under Article 32:

Evaluate:

 Encryption at rest
 Encryption in transit
 MFA
 Role-based access
 Logging and monitoring
 Backup controls

✅ Step 11: Build the Record of Processing


Activities (ROPA)
Your data map feeds directly into:

 Purpose of processing
 Categories of data
 Categories of recipients
 Transfers
 Retention periods
 Security measures

5️⃣ Practical Example (Case Study)


Scenario: Online Retail Company

Step 1 – Collection

 Name, email, address, payment details

Step 2 – Storage

 E-commerce platform
 Payment gateway
 Cloud storage

Step 3 – Usage

 Order processing
 Marketing emails
 Fraud detection

Step 4 – Sharing

 Logistics company
 Payment processor
 Email marketing tool
Step 5 – Retention

 Transaction records: 7 years


 Marketing data: Until opt-out

Step 6 – Security

 TLS encryption
 Tokenized payment data
 Access control

6️⃣ Tools for Data Mapping


Organizations use:

 Excel (basic inventory)


 Microsoft Purview
 OneTrust
 TrustArc
 ServiceNow IRM
 Collibra
 Data discovery tools

You might also like