Data mapping under the EU GDPR
To comply with the EU GDPR (General Data Protection Regulation), organisations need to map their data flows to assess privacy risks.
Organisations must identify what personal data they process, where it comes from, where it goes, and what systems and processes are used to store, transfer or process the data.
This data mapping process will help organisations:
- Understand what personal data they hold and why;
- Identify and assess any risks to individuals’ privacy;
- Put in place measures to mitigate those risks; and
- Comply with their obligations under the GDPR.
Data mapping is also a useful tool for DPIAs (data protection impact assessments).
For comprehensive guidance and practical advice on complying with the GDPR, read our bestselling book EU General Data Protection Regulation (GDPR) – An implementation and compliance guide, fourth edition.