Data Mapping under the GDPR – Detailed
Overview & Step-by-Step Guide
Data mapping is a foundational requirement for compliance with
the General Data Protection Regulation (GDPR). It enables
organizations to understand:
What personal data they collect
Why they collect it
Where it flows
Who has access to it
How long they retain it
How it is protected
Without data mapping, compliance with GDPR Articles 5, 6, 30,
32, and 35 becomes nearly impossible.
1️⃣ What is Data Mapping?
Data mapping is the process of documenting the lifecycle of
personal data within an organization — from collection to deletion.
It visually or structurally shows:
Collection → Storage → Usage → Sharing → Archiving → Deletion
2️⃣ Why Data Mapping is Critical
for GDPR
Under GDPR, organizations must demonstrate:
🔹 Accountability (Article 5(2))
You must prove compliance.
🔹 Records of Processing Activities (ROPA) – Article 30
Data mapping feeds directly into ROPA documentation.
🔹 Data Protection Impact Assessments (DPIA) – Article 35
You cannot assess risk if you don’t know where data flows.
🔹 Data Subject Rights
To respond to:
Access requests
Erasure requests
Portability requests
You must know exactly where the data resides.
3️⃣ What Must Be Mapped?
Under GDPR, data mapping should identify:
A. Categories of Personal Data
Names
ID numbers
Email addresses
IP addresses
Location data
Financial data
Health data (special category)
B. Data Subjects
Customers
Employees
Vendors
Website visitors
C. Lawful Basis (Article 6)
Consent
Contract
Legal obligation
Legitimate interest
Vital interests
Public task
D. Systems & Storage Locations
CRM systems
HR systems
Email servers
Cloud storage
Backup systems
Paper files
E. Data Transfers
Third-party processors
Cloud providers
Cross-border transfers outside EU
F. Retention Periods
G. Security Controls
Encryption
Access controls
Monitoring
Data masking
4️⃣ Step-by-Step Data Mapping
Process
✅ Step 1: Define Scope
Determine:
Which business units?
Which jurisdictions?
Which systems?
Example:
HR Department
Marketing Department
Finance Department
✅ Step 2: Identify Data Collection Points
Where is personal data collected?
Website forms
Job applications
Contracts
Mobile apps
CCTV systems
Customer onboarding
Create a Data Inventory List.
✅ Step 3: Conduct Stakeholder Interviews
Meet with:
IT
HR
Marketing
Legal
Security
Operations
Ask:
What personal data do you collect?
Why?
Where is it stored?
Who accesses it?
Is it shared externally?
✅ Step 4: Identify Data Elements
Example:
Process Data Collected Data Subject
Recruitment CV, ID number Job applicant
Payroll Bank account Employee
CRM Email, phone Customer
✅ Step 5: Document Data Flows
Map how data moves:
Website → CRM → Marketing tool → Email platform → Cloud backup
Use:
Flow diagrams
Swimlane diagrams
Data flow charts
✅ Step 6: Identify Lawful Basis
For each processing activity, document:
Processing Activity Lawful Basis
Payroll Legal
obligation
Marketing emails Consent
Service delivery Contract
✅ Step 7: Identify Third-Party Processors
Document:
Cloud providers
Payroll vendors
CRM providers
IT support
Check:
Data Processing Agreements (DPAs)
Cross-border transfer safeguards (SCCs)
✅ Step 8: Identify International Transfers
If data leaves the EU:
Adequacy decision?
Standard Contractual Clauses?
Binding Corporate Rules?
✅ Step 9: Define Retention & Deletion Rules
Example:
Data Type Retention Period
CVs 6 months
Payroll 5–7 years
records
Marketing data Until consent withdrawn
✅ Step 10: Assess Security Controls
Under Article 32:
Evaluate:
Encryption at rest
Encryption in transit
MFA
Role-based access
Logging and monitoring
Backup controls
✅ Step 11: Build the Record of Processing
Activities (ROPA)
Your data map feeds directly into:
Purpose of processing
Categories of data
Categories of recipients
Transfers
Retention periods
Security measures
5️⃣ Practical Example (Case Study)
Scenario: Online Retail Company
Step 1 – Collection
Name, email, address, payment details
Step 2 – Storage
E-commerce platform
Payment gateway
Cloud storage
Step 3 – Usage
Order processing
Marketing emails
Fraud detection
Step 4 – Sharing
Logistics company
Payment processor
Email marketing tool
Step 5 – Retention
Transaction records: 7 years
Marketing data: Until opt-out
Step 6 – Security
TLS encryption
Tokenized payment data
Access control
6️⃣ Tools for Data Mapping
Organizations use:
Excel (basic inventory)
Microsoft Purview
OneTrust
TrustArc
ServiceNow IRM
Collibra
Data discovery tools