A data map or RoPA is only useful if it reflects what the business actually does. I build records at the processing activity level, based on stakeholder interviews and documentation review rather than a survey circulated to system owners.
Data mapping is the process of identifying and recording the personal data processing carried out within an organization. A RoPA is a specifically structured form of data mapping required under the GDPR and UK GDPR, and is mandatory for companies subject to those regimes, subject to limited exemptions.
More broadly, data mapping is the foundation of any functioning privacy program, because a company cannot comply with obligations it has not identified or manage risk it cannot see.
Mapping identifies which regulations apply to your processing and what their requirements demand of the business.
Identify every third party receiving personal data and ensure appropriate contractual safeguards are in place.
Identify high-risk processing so that proportionate controls can be applied where they are actually needed.
Privacy notices, policies, and SOPs can only be accurate if they reflect what the business actually does with personal data.
The search cannot be complete without knowing where the data sits. A current, accurate map is a prerequisite for a defensible DSR response.
Typically an audit finding, a regulatory finding, or a program requirement where the map is a prerequisite for the work that follows.
Companies also come to this when an enterprise customer or investor asks for evidence of their processing records, when a data subject request exposes that nobody knows which systems hold the data, or when growth and acquisition have left the business without a current picture of what it processes and where.
Interview key stakeholders, which may include legal, infosec, IT, procurement, HR, marketing, and operations.
Review existing privacy documentation, procurement records, system inventories, and contracts.
Map the personal data collected and processed, together with the data flows, retention, recipients, and cross-border transfers.
Draft the data map or RoPA, as required by the business's regulatory obligations.
Circulate the draft to key stakeholders for review and comment.
Incorporate feedback and finalise the data map or RoPA.
Draft the SOP for monitoring and maintaining the record, with defined ownership and review cadence.
The exercise most often gets run as a survey circulated to system owners. That captures what people believe happens rather than what the systems actually do, and it misses processing that sits outside IT's visibility — including tools procured on a corporate card, spreadsheets held locally, and data held by third parties on the company's behalf.
Records are built at the system level rather than the processing activity level, which makes them impossible to use for assessing legal basis or retention. Detail is inconsistent, with some entries specifying data elements and others describing categories in the abstract.
And once built, the record is not maintained. It diverges from the business within a quarter and cannot be relied on when a regulator, an auditor, or a data subject request tests it.
An influencer marketing platform needed to understand its legal obligations but had no clear picture of the personal data it processed, which spanned platform users, creators, brand clients, and data received from third-party sources. I mapped the processing end to end, capturing what was collected, why, where it flowed, who received it, and how long it was retained.
That gave the business a defensible view of which regulations applied to it, where its third-party exposure sat, and which processing needed controls, and it became the basis for the privacy notices and policies that followed.
A RoPA is mandatory for companies subject to the GDPR and UK GDPR, subject to limited exemptions. Whether your organization falls within scope depends on your processing activities and where you operate. This is the kind of question the mapping exercise is designed to answer.
A survey captures what people believe happens rather than what the systems actually do. It misses processing that sits outside IT's visibility — tools procured on a corporate card, spreadsheets held locally, and data held by third parties on the company's behalf. Interviews, combined with documentation and contract review, are how you find what a survey will not.
The engagement includes a maintenance SOP with defined ownership and review cadence. Ongoing maintenance itself is not included in the project fee but is available for an additional fee or under retainer. A record that is not maintained diverges from the business within a quarter and cannot be relied on when a regulator, auditor, or data subject request tests it.
The engagement does not include technical discovery or data scanning tooling, platform configuration, remediation of issues identified during mapping, or contract renegotiation with third parties. Those are scoped separately. The work produces a complete, accurate record and a SOP to maintain it — acting on what the record reveals is distinct work.
Data mapping is fixed scope and fixed fee. The number is agreed before anything starts.
A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.
We use Google Analytics 4 to understand how this site is used and to measure our advertising. These set cookies on your device. Nothing loads until you choose. How we handle your data.