Data Mapping & RoPA

Know What You Process, Where It Goes, and What That Means

A data map or RoPA is only useful if it reflects what the business actually does. I build records at the processing activity level, based on stakeholder interviews and documentation review rather than a survey circulated to system owners.

What Data Mapping Is and Why It Matters

Data mapping is the process of identifying and recording the personal data processing carried out within an organization. A RoPA is a specifically structured form of data mapping required under the GDPR and UK GDPR, and is mandatory for companies subject to those regimes, subject to limited exemptions.

More broadly, data mapping is the foundation of any functioning privacy program, because a company cannot comply with obligations it has not identified or manage risk it cannot see.

What Mapping the Processing Allows You to Do

  1. 01

    Assess applicable regulations

    Mapping identifies which regulations apply to your processing and what their requirements demand of the business.

  2. 02

    Manage third-party exposure

    Identify every third party receiving personal data and ensure appropriate contractual safeguards are in place.

  3. 03

    Implement proportionate controls

    Identify high-risk processing so that proportionate controls can be applied where they are actually needed.

  4. 04

    Draft accurate notices and policies

    Privacy notices, policies, and SOPs can only be accurate if they reflect what the business actually does with personal data.

  5. 05

    Respond to data subject requests

    The search cannot be complete without knowing where the data sits. A current, accurate map is a prerequisite for a defensible DSR response.

What Typically Prompts This Work

Typically an audit finding, a regulatory finding, or a program requirement where the map is a prerequisite for the work that follows.

Companies also come to this when an enterprise customer or investor asks for evidence of their processing records, when a data subject request exposes that nobody knows which systems hold the data, or when growth and acquisition have left the business without a current picture of what it processes and where.

How the Engagement Works

  1. 01

    Stakeholder interviews

    Interview key stakeholders, which may include legal, infosec, IT, procurement, HR, marketing, and operations.

  2. 02

    Documentation review

    Review existing privacy documentation, procurement records, system inventories, and contracts.

  3. 03

    Mapping

    Map the personal data collected and processed, together with the data flows, retention, recipients, and cross-border transfers.

  4. 04

    Draft

    Draft the data map or RoPA, as required by the business's regulatory obligations.

  5. 05

    Stakeholder review

    Circulate the draft to key stakeholders for review and comment.

  6. 06

    Finalise

    Incorporate feedback and finalise the data map or RoPA.

  7. 07

    Maintenance SOP

    Draft the SOP for monitoring and maintaining the record, with defined ownership and review cadence.

Fees and Timeline

Engagement model
Fixed fee project The number is agreed before anything starts.
Delivery timeline
One to three months Depends on complexity, the number of business functions and systems involved, and stakeholder availability.
Ongoing maintenance
Available separately Priced as an add-on or under retainer. Not included in the project fee.

Why Data Maps Fail in Practice

The exercise most often gets run as a survey circulated to system owners. That captures what people believe happens rather than what the systems actually do, and it misses processing that sits outside IT's visibility — including tools procured on a corporate card, spreadsheets held locally, and data held by third parties on the company's behalf.

Records are built at the system level rather than the processing activity level, which makes them impossible to use for assessing legal basis or retention. Detail is inconsistent, with some entries specifying data elements and others describing categories in the abstract.

And once built, the record is not maintained. It diverges from the business within a quarter and cannot be relied on when a regulator, an auditor, or a data subject request tests it.

What Is and Is Not Included

Included

  • Stakeholder interviews and documentation review
  • Complete data map or RoPA based on the information provided
  • Data flow, recipient, retention, and transfer detail
  • SOP for the maintenance of the data map or RoPA

Not included

  • Ongoing maintenance — available for an additional fee or under retainer
  • Technical discovery or data scanning tooling, and any platform configuration
  • Remediation of issues identified during mapping, scoped separately
  • Contract renegotiation with third parties identified

How This Has Worked in Practice

An influencer marketing platform needed to understand its legal obligations but had no clear picture of the personal data it processed, which spanned platform users, creators, brand clients, and data received from third-party sources. I mapped the processing end to end, capturing what was collected, why, where it flowed, who received it, and how long it was retained.

That gave the business a defensible view of which regulations applied to it, where its third-party exposure sat, and which processing needed controls, and it became the basis for the privacy notices and policies that followed.

Common Questions

Is a RoPA mandatory for my organization?

A RoPA is mandatory for companies subject to the GDPR and UK GDPR, subject to limited exemptions. Whether your organization falls within scope depends on your processing activities and where you operate. This is the kind of question the mapping exercise is designed to answer.

Why not just run a survey to system owners rather than conduct interviews?

A survey captures what people believe happens rather than what the systems actually do. It misses processing that sits outside IT's visibility — tools procured on a corporate card, spreadsheets held locally, and data held by third parties on the company's behalf. Interviews, combined with documentation and contract review, are how you find what a survey will not.

What happens to the record after the project closes?

The engagement includes a maintenance SOP with defined ownership and review cadence. Ongoing maintenance itself is not included in the project fee but is available for an additional fee or under retainer. A record that is not maintained diverges from the business within a quarter and cannot be relied on when a regulator, auditor, or data subject request tests it.

What is not covered by this engagement?

The engagement does not include technical discovery or data scanning tooling, platform configuration, remediation of issues identified during mapping, or contract renegotiation with third parties. Those are scoped separately. The work produces a complete, accurate record and a SOP to maintain it — acting on what the record reveals is distinct work.

Our services

Ready to scope the work?

Get in touch

Data mapping is fixed scope and fixed fee. The number is agreed before anything starts.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.