Every privacy program rests on one unglamorous task: knowing what personal data you hold, where it lives, and where it goes. That is data mapping. It is not the exciting part of privacy, and it is the part everything else depends on. You cannot honor a data subject request, respond to a breach, or answer a regulator about data you cannot find.
Here is what a data map is, what it captures, and how to keep it from going stale the day after you finish it.
What a Data Map Is
A data map, sometimes called a record of processing, is an inventory of the personal data your organization handles. For each type of data, it records where it comes from, why you have it, where it is stored, who can access it, who you share it with, and how long you keep it. It turns a vague sense of what you collect into a documented picture you can act on.
Why It Comes First
Nearly every privacy obligation traces back to the data map. Responding to an access or deletion request means finding every copy of a person's data. Meeting retention rules means knowing what you hold and for how long. Demonstrating a lawful basis means knowing why you have each dataset. Assessing risk means knowing what is sensitive and where it flows. Skip the map and every one of these becomes guesswork.
What to Capture
- The categories of personal data you hold, including any sensitive categories.
- The source of each: collected directly, from a third party, or generated internally.
- The purpose and lawful basis for each processing activity.
- Where the data is stored, including cloud services and vendor systems.
- Who has access internally and which third parties you share it with.
- Retention periods and how data is deleted.
The goal is not a perfect academic model. It is a working picture accurate enough to answer real questions quickly.
Where Companies Underestimate It
The common surprise is scope. Personal data spreads further than anyone expects: spreadsheets, support tickets, marketing tools, backups, vendor platforms, and the AI tools employees now paste data into. A map that only covers the main database misses most of the exposure. The uncomfortable directories, shadow systems, and vendor tools are exactly where risk hides.
Keep It Current
A data map is only useful if it reflects reality. New tools, new data flows, and new vendors change the picture constantly. Treat the map as a living document with an owner and a review cadence, not a one-time project. A map that was accurate at launch and ignored since is worse than no map, because it creates false confidence.
It Feeds Everything Else
Done well, the data map powers the rest of your privacy program. It drives your record of processing, your controller and processor role assignments, your risk assessments, and your readiness for ISO 27701 or a regulator's questions. The unglamorous work up front is what makes everything downstream possible.
Frequently Asked Questions
What is the difference between a data map and a record of processing?
They overlap heavily. A record of processing is the formal documentation some laws require. A data map is the broader working inventory it draws from. In practice, a good data map produces your record of processing.
How often should we update the data map?
On a regular cadence and whenever something material changes: a new system, a new vendor, or a new type of data. Assign an owner so it does not drift.
Do we need a data map for ISO 27701?
Effectively yes. You cannot scope a privacy management system or assign controller and processor roles without knowing what data you process and where it flows.
If your privacy program does not start with a current data map, it starts on sand. A readiness assessment builds the map and the program on top of it. Talk with a senior advisor at JBW Group.