Scope and data-source planning
Define business units, jurisdictions, data types, repositories, third parties, exclusions, access dependencies, and evidence standards.
Dataconsultant identifies personal and sensitive data across structured and unstructured environments, maps how it moves, and evaluates ownership, retention, access, duplication, and regulatory exposure. The assessment supports privacy, security, compliance, data, and technology leaders with evidence-based findings and a practical remediation plan.
A personal data discovery assessment creates an evidence-based view of personal and sensitive data across systems, repositories, interfaces, and third parties. It helps organisations understand where data is held, why it is used, who can access it, how long it is retained, and which gaps require remediation.
The work can combine stakeholder evidence, policy review, platform inventories, targeted technical discovery, sampling, interviews, and validation. Coverage and confidence are documented so decision-makers can distinguish verified findings from assumptions or inaccessible areas.
The engagement is structured to produce a reliable discovery baseline without creating unnecessary operational disruption or excessive evidence collection.
Define business units, jurisdictions, data types, repositories, third parties, exclusions, access dependencies, and evidence standards.
Locate personal and sensitive data using approved inventories, queries, scanning tools, sampling, interviews, and document review.
Review data movement, sharing, access, retention, duplication, ownership, residency, and control effectiveness.
Validate evidence, rank risks, identify dependencies, and produce practical actions with accountable owners and decision points.
Reconcile documented records with technical and operational evidence so gaps, unknown repositories, and ownership uncertainty become visible.
Separate urgent exposure from lower-impact housekeeping by considering sensitivity, volume, access, retention, sharing, and regulatory context.
Translate findings into an ordered plan spanning privacy, security, data governance, records management, application ownership, and third parties.
Records of processing and system registers may not reflect new SaaS tools, local files, analytics copies, archives, or integration flows.
Reconcile inventories with stakeholder and technical evidence, record confidence levels, and identify repositories requiring deeper review.
Personal data may persist in exports, backups, collaboration folders, test environments, or obsolete applications beyond its intended lifecycle.
Identify likely duplication and retention hotspots, validate business purpose, and define actions for deletion, minimisation, archival, or ownership.
Permissions, vendor integrations, cross-border transfers, and data-sharing arrangements can be difficult to evidence consistently.
Map access paths and recipients, flag control gaps and contractual dependencies, and route specialist issues for privacy, legal, security, or procurement review.
Start with a focused scope covering the highest-risk systems, data types, or business units.
Build or refresh an inventory before policy, retention, data-subject-rights, consent, or governance improvements.
Identify personal data, transfer dependencies, residency constraints, and remediation needs before moving or decommissioning systems.
Improve evidence for internal review, compliance assessment, control testing, or external assurance preparation.
Understand inherited personal-data estates, unknown repositories, third-party dependencies, and integration risk.
Clarify whether datasets contain personal or sensitive information before model training, experimentation, enrichment, or broader reuse.
Locate obsolete, duplicated, over-retained, or poorly owned data and create a controlled remediation backlog.
Build a defensible view of relevant environments.
Applications, databases, warehouses, file stores, collaboration platforms, archives, endpoints, interfaces, and third-party exchanges.
Approved scanning, metadata inspection, queries, sampling, document review, interviews, and reconciliation of existing registers.
Assess how personal data is handled and governed.
Personal, sensitive, special-category, financial, identity, behavioural, employee, customer, child, or other context-specific data.
Purpose, collection, access, sharing, transfer, duplication, retention, deletion, residency, security, ownership, and third-party control considerations.
| Deliverable | What it contains | How it supports decisions |
|---|---|---|
| Assessment scope and evidence register | Systems, repositories, data types, exclusions, access status, evidence sources, assumptions, and limitations. | Shows what was assessed and where confidence or follow-up work is required. |
| Personal data inventory | Data categories, locations, business purpose, ownership, sensitivity, recipients, and indicative lifecycle information. | Provides a practical baseline for privacy, governance, security, and records work. |
| Data-flow and exposure observations | Transfers, integrations, exports, third-party exchanges, access paths, duplication points, and residency concerns. | Helps teams understand operational exposure and cross-functional dependencies. |
| Risk-ranked findings register | Finding, evidence, impact, affected systems, control context, priority, owner, dependency, and recommended action. | Supports transparent prioritisation and accountable remediation. |
| Executive assessment report | Material themes, limitations, decisions required, remediation roadmap, governance actions, and measurement approach. | Enables leadership, risk, privacy, security, and technology teams to align on next steps. |
We can shape the evidence structure, reporting depth, and governance outputs around the intended decision or assurance need.
Confirm business drivers, jurisdictions, systems, data types, stakeholders, risk priorities, evidence standards, and exclusions.
Primary output: approved assessment charterGather inventories, policies, architecture, contracts, retention rules, prior findings, and approved access to selected environments.
Primary output: evidence and access registerUse proportionate technical discovery, sampling, interviews, metadata review, and repository analysis to locate and classify data.
Primary output: discovery findings baselineReview data movement, recipients, permissions, lifecycle, ownership, third parties, residency, and relevant privacy or security controls.
Primary output: flow and control observationsTest findings with accountable teams, resolve material inconsistencies, record limitations, and rank remediation using agreed criteria.
Primary output: validated risk registerPresent executive findings, detailed evidence, decisions, remediation actions, ownership, dependencies, and repeat-assessment options.
Primary output: final report and action planDiscovery methods and reference frameworks are selected according to scope, platform support, security requirements, jurisdictions, internal policy, and the intended use of findings.
Scope can be phased by risk, platform, business unit, jurisdiction, or data category.
| Model | Best suited to | Typical scope | Client participation |
|---|---|---|---|
| Focused assessment | A defined system, business unit, data type, or regulatory concern. | Targeted discovery, validation, findings, and prioritised actions. | System owner, privacy, security, and technical access support. |
| Enterprise assessment | Broad privacy baseline, transformation, audit readiness, or governance improvement. | Multi-domain scope, phased discovery, data-flow analysis, governance findings, and roadmap. | Executive sponsor, programme lead, data owners, platform teams, legal, risk, and compliance. |
| Assessment plus remediation | Organisations that need support moving from findings into controlled change. | Assessment, remediation planning, ownership, control design, implementation support, and validation. | Joint delivery team and clear decision rights. |
| Managed monitoring | Dynamic environments requiring repeat discovery and governance reporting. | Scheduled scans or reviews, change tracking, issue management, metrics, and improvement cycles. | Operational owners, secure access, review cadence, and escalation routes. |
These examples illustrate delivery patterns rather than actual client results.
A retailer needs to reconcile CRM, ecommerce, support, marketing, analytics, and file-based exports before redesigning retention and access controls.
Illustrative output: cross-platform inventory, duplicate-data hotspots, third-party flows, and prioritised retention actions.
A professional-services group needs visibility across HR, payroll, recruitment, collaboration, local drives, and archived employee documents.
Illustrative output: sensitive-data map, ownership gaps, access observations, and lifecycle remediation backlog.
An enterprise wants to identify personal data and residency constraints before migrating applications and retiring legacy infrastructure.
Illustrative output: migration-relevant classification, flow dependencies, control requirements, and decommissioning checks.
Baselines, measurement rules, ownership, data quality, and attribution limits should be agreed before KPIs are used for formal reporting.
Number of business units, jurisdictions, systems, repositories, data categories, and third parties.
Data volume, platform support, legacy environments, integration patterns, access controls, and unstructured content.
Inventory-only work versus classification, flow mapping, control review, risk analysis, and remediation planning.
Stakeholder availability, access approvals, onsite work, tooling licences, security reviews, and evidence quality.
A written estimate can be prepared after reviewing the intended outcome, scope, platforms, access model, and deliverables.
Findings distinguish verified evidence, stakeholder statements, assumptions, inaccessible areas, and limitations so decisions remain transparent.
The assessment connects technical discovery with ownership, purpose, lifecycle, regulatory context, and practical remediation dependencies.
Support can stop at assessment or continue into roadmap mobilisation, control improvement, governance setup, repeat discovery, and capability building.
Clarify the decision, evidence, systems, risks, and stakeholders that should shape the assessment.
Use approved access, least privilege, encryption, controlled exports, logging, restricted evidence sharing, and agreed deletion or retention.
Apply evidence registers, sampling logic, validation workshops, issue traceability, peer review, version control, and documented limitations.
Minimise assessment data, avoid unnecessary copying, define purpose, restrict access, and route sensitive decisions to accountable specialists.
Map relevant obligations and control gaps while recognising that legal advice, certification, statutory audit, and formal regulatory opinions require authorised providers.
The assessment can connect business applications, data platforms, unstructured repositories, governance evidence, and third-party dependencies into one controlled discovery model.
The following role-based testimonials are illustrative of the delivery experience and concerns organisations may have when undertaking this type of assessment; they are not presented as verified client reviews.
“The assessment gave our privacy team a much clearer evidence base than the system register alone. Workshops, repository sampling, and validation were handled carefully, and the final findings separated confirmed issues from areas that still needed access or legal review.”
“Security and privacy responsibilities were addressed together rather than as separate workstreams. The team documented access paths, evidence limitations, third-party dependencies, and remediation ownership in a way our control owners could use without reinterpreting the report.”
“The discovery work was practical across a mixed estate of databases, collaboration tools, analytics copies, and local exports. Revision handling was structured, and our technical teams could trace each material finding back to the source evidence and validation discussion.”
“We needed discovery findings that could inform migration sequencing, not just a compliance document. The team connected personal-data classifications with application dependencies, residency questions, decommissioning risks, and decision points for our cloud programme.”
“The evidence register and finding structure made internal review easier. Assumptions, inaccessible repositories, sampling decisions, and control gaps were transparent, which helped us focus follow-up testing and avoid treating every observation as the same level of risk.”
“Communication remained clear across privacy, legal, operations, and technology stakeholders. The remediation plan included ownership, dependencies, escalation points, and knowledge transfer, so the assessment could move into an operating programme rather than remain a static report.”
Direct answers on scope, delivery, technology, governance, pricing, limitations, and follow-on support.
A personal data discovery assessment identifies where personal and sensitive data is stored, processed, transferred, duplicated, retained, and accessed across an organisation. Scope depends on systems, jurisdictions, data types, and available evidence. The assessment provides an evidence-based inventory and risk view; it does not by itself constitute legal advice or regulatory certification.
The scope can include business applications, databases, cloud storage, collaboration tools, file shares, data warehouses, analytics platforms, endpoints, archives, third-party exchanges, and selected unstructured repositories. Final coverage depends on agreed systems, access permissions, technical feasibility, sampling decisions, and regulatory priorities.
The service is suitable for organisations that lack a reliable personal-data inventory, are preparing for privacy compliance work, have experienced rapid platform growth, are completing due diligence, or need evidence for remediation planning. A narrower records review may be more proportionate when the environment is small and already well documented.
Typical deliverables include a scoped data-source register, personal-data inventory, system and repository findings, data-flow observations, classification results, risk-ranked issues, retention and duplication concerns, ownership gaps, third-party dependencies, remediation recommendations, and an executive summary. Deliverables are tailored to the agreed depth and evidence available.
The assessment usually progresses through scope confirmation, stakeholder discovery, evidence collection, technical scanning or sampling, classification review, data-flow analysis, risk evaluation, validation workshops, and final reporting. The sequence depends on access readiness, repository volume, tooling, legal constraints, and the need to minimise operational disruption.
There is no reliable fixed duration before scoping. Timing depends on repository count, data volume, geographic coverage, system complexity, access approvals, technical scanning constraints, stakeholder availability, validation cycles, and whether remediation planning is included. A phased assessment can prioritise the highest-risk environments first.
Pricing is generally based on assessment scope, number and type of systems, data volume, jurisdictions, discovery tooling, access complexity, onsite needs, evidence quality, stakeholder workshops, reporting depth, and optional remediation support. Dataconsultant can provide a written estimate after an initial scope and dependency review.
The assessment can cover common cloud platforms, databases, data warehouses, file shares, collaboration suites, SaaS applications, CRM and ERP systems, analytics environments, document repositories, and selected endpoint or archive sources. Technical methods are chosen according to platform support, security requirements, licensing, and approved access.
Relevant reference points may include applicable data-protection laws, recognised privacy-management standards, information-security controls, records-management requirements, sector obligations, contractual commitments, and internal policies. The exact framework set depends on jurisdiction and context and should be validated by authorised legal, privacy, security, and compliance specialists.
Discovery is planned with least-privilege access, approved credentials, secure evidence handling, controlled exports, logging, encryption, and defined retention of assessment data. The precise controls depend on client policy and platform capability. The service does not replace penetration testing, incident response, or a full cybersecurity assessment unless separately commissioned.
The client normally retains ownership of its data and receives the agreed assessment outputs, subject to contract terms. Dataconsultant uses the information only for authorised delivery purposes and applies agreed confidentiality, access, retention, and deletion controls. Intellectual-property terms for reusable methods, templates, and tools should be confirmed in the engagement agreement.
Yes. Follow-on support can include remediation planning, data minimisation, retention improvement, ownership assignment, data-flow documentation, privacy-control design, platform configuration, repeat discovery, governance reporting, managed monitoring, and capability building. Responsibilities, acceptance criteria, and legal or security review requirements are scoped separately.