Inventory discovery
Identify processing activities, personal-data stores, interfaces, business owners, vendors, and evidence sources across functions and jurisdictions.
DataConsultant helps privacy, legal, risk, security, data, and technology teams identify where personal data exists, why it is processed, who owns it, how it moves, who receives it, and how long it is retained. The result is a structured privacy data inventory that supports regulatory records, risk assessment, data-subject rights, retention decisions, and accountable control improvement.
A privacy data inventory is a structured record of personal data and the processing activities that use it. It connects data categories and data subjects with purposes, lawful bases, systems, owners, recipients, international transfers, retention periods, security measures, privacy risks, and related obligations.
It may support a record of processing activities, but the required fields and legal interpretation depend on applicable law and organisational context.
The engagement can start with discovery, remediation, or implementation and can extend into operating-model design, platform configuration, assurance, training, and managed maintenance.
Identify processing activities, personal-data stores, interfaces, business owners, vendors, and evidence sources across functions and jurisdictions.
Define the data model, field definitions, taxonomy, ownership, review workflow, evidence standards, and relationship to policies and assessments.
Run interviews, surveys, system reviews, document analysis, and data-flow validation to create or improve inventory records.
Establish update triggers, assurance checks, reporting, issue management, training, integrations, and managed maintenance.
The value comes from making privacy information connected, owned, reviewable, and usable rather than collecting isolated spreadsheet fields.
Support records of processing, accountability evidence, impact assessments, regulator enquiries, and internal compliance review.
Reduce repeated fact-finding for rights requests, incidents, retention reviews, vendor assessments, and project approvals.
Identify sensitive data, unsupported purposes, unclear ownership, excessive retention, uncontrolled transfers, and weak safeguards.
Connect new systems, products, vendors, and data uses to review triggers and inventory updates.
Link collection, use, sharing, storage, retention, deletion, and archival decisions across systems and business processes.
Clarify who supplies information, who approves a record, who owns controls, and who resolves gaps.
DataConsultant focuses on gaps that prevent privacy teams from obtaining reliable, current, and decision-ready information.
Business applications, shared drives, analytics platforms, SaaS tools, archives, and supplier environments are documented inconsistently or not at all.
Lists of fields or databases do not establish the business purpose, lawful basis, data subjects, recipients, or control responsibilities.
New projects, vendors, integrations, data products, and retention changes are not connected to an operating update process.
Privacy teams chase information while business, product, data, and system owners remain unclear about approval and maintenance duties.
Recipients, subprocessors, jurisdictions, interfaces, and downstream uses are recorded separately, making risk review difficult.
Retention, access, minimisation, notice, consent, security, or contractual issues are observed but not assigned, prioritised, and tracked.
Discuss the scope, evidence sources, jurisdictions, systems, and maintenance model required for your organisation.
A privacy inventory can support strategic compliance programmes and routine operational decisions.
Establish processing-activity records, field standards, evidence, ownership, validation, and review cycles.
Provide dependable facts about data subjects, purposes, flows, systems, recipients, risks, and safeguards.
Identify likely data locations, owners, processors, retention rules, and dependencies that affect response handling.
Connect policy periods to processing purposes, systems, records, exceptions, legal holds, and accountable owners.
Map recipients, processors, subprocessors, locations, transfer mechanisms, contracts, and control dependencies.
Discover inherited data uses, duplicated records, conflicting practices, platform changes, and remediation priorities.
Scope is tailored to the organisation’s risk profile, regulatory context, technology estate, and existing privacy operating model.
Find and validate the source facts.
Stakeholder interviews, system inventories, architecture and integration reviews, policy and contract analysis, questionnaires, sample testing, and reconciliation with existing registers.
Define what a complete record means.
Purpose, data subjects, data categories, source, collection method, lawful basis, special-category handling, recipients, transfers, retention, ownership, security measures, risk, status, and review dates.
Connect processing across the lifecycle.
Map collection, ingestion, use, enrichment, analytics, sharing, export, storage, archive, and deletion, with attention to downstream recipients and jurisdictional movement.
Make findings actionable.
Link records to notices, consent, contracts, impact assessments, retention schedules, security controls, incidents, rights handling, issues, remediation, and acceptance decisions.
Keep the inventory current.
Define roles, update triggers, approval workflows, change-management integration, reporting, platform requirements, data migration, integrations, training, and managed-service procedures.
Deliverables are agreed during discovery and can be supplied in business-readable, implementation-ready, and platform-import formats.
| Deliverable | Purpose | Typical contents | Client input |
|---|---|---|---|
| Inventory design specification | Define the record structure and standards | Fields, definitions, taxonomies, relationships, validation rules, evidence, lifecycle status | Policies, legal interpretation, internal terminology |
| Processing activity inventory | Document personal-data processing | Purpose, data subjects, categories, basis, systems, owners, recipients, transfers, retention, controls | Stakeholder and system-owner validation |
| Privacy data-flow maps | Show movement and dependencies | Sources, interfaces, transformations, recipients, vendors, jurisdictions, stores, deletion points | Architecture, integration, vendor, and operations evidence |
| Gap and risk register | Turn findings into action | Missing evidence, ownership gaps, control issues, risk rating, action, owner, target date | Risk criteria and acceptance authority |
| Governance and operating model | Keep records accurate | Roles, RACI, workflows, triggers, approvals, reviews, assurance, escalation, reporting | Organisation and decision-rights input |
| Technology requirements | Support platform selection or configuration | Use cases, users, fields, workflow, integration, reporting, security, migration, acceptance criteria | Architecture, security, procurement, and platform constraints |
| Management dashboard | Support oversight | Coverage, completeness, review status, high-risk processing, overdue actions, ownership, trends | Approved KPI definitions and baselines |
Scope the inventory, maps, risk register, operating model, platform requirements, and assurance pack around your decision needs.
The process is evidence-led and adapts to whether the organisation needs an initial inventory, remediation, technology implementation, or managed maintenance.
Confirm business objectives, jurisdictions, relevant policies, processing boundaries, risk priorities, and required outputs.
Output: scope, assumptions, stakeholder plan
Define record types, fields, taxonomies, evidence, ownership, quality rules, workflow, and reporting needs.
Output: inventory specification
Review systems, documents, contracts, existing registers, architecture, surveys, and stakeholder responses.
Output: evidence register and draft records
Connect purposes, data, subjects, systems, owners, recipients, vendors, transfers, retention, and safeguards.
Output: validated inventory and data maps
Test completeness, consistency, traceability, ownership, evidence, control alignment, and unresolved decisions.
Output: findings and remediation register
Configure workflows, migrate records, integrate change triggers, establish reporting, and assign responsibilities.
Output: operating inventory and controls
Run quality assurance, stakeholder approval, user testing, management review, training, and documentation.
Output: approved inventory and handover pack
Support periodic reviews, event-driven updates, monitoring, issue closure, assurance, and taxonomy improvement.
Output: reporting and continuous-improvement cycle
Technology and framework choices must fit the organisation’s obligations, evidence, architecture, security, procurement model, and operating capacity.
Legal obligations and interpretations should be confirmed by authorised legal or privacy specialists. Framework references do not imply certification.
Review platform options, integrations, workflows, security constraints, migration needs, and ownership before implementation.
| Model | Best for | Typical scope | Commercial basis | Key dependency |
|---|---|---|---|---|
| Fixed-scope assessment | Known inventory problem or audit preparation | Review, findings, recommendations, prioritised plan | Project fee | Evidence and stakeholder access |
| Inventory build or remediation | Creating or rebuilding records | Design, discovery, population, validation, handover | Milestone or project fee | Timely business-owner participation |
| Platform implementation support | Technology selection, migration, or configuration | Requirements, data model, workflow, migration, testing, adoption | Project or capacity-based | Vendor, architecture, and security coordination |
| Dedicated specialist capacity | Variable backlog and internal team support | Analysts, privacy data specialists, governance, QA, reporting | Time and materials | Clear prioritisation and retained client accountability |
| Managed inventory service | Ongoing maintenance and assurance | Updates, review cycles, quality checks, reporting, issue tracking | Recurring service fee | Defined update triggers, SLAs, and escalation |
| Training and capability building | Internal ownership and sustainable operation | Role training, playbooks, templates, coaching, quality calibration | Workshop or programme fee | Named process and control owners |
This example shows how an inventory can structure a customer-support activity. It is illustrative and does not represent a client result.
Illustrative processing activity for operational planning and control design.
Purpose, basis, data subjects, categories, source, systems, owner, recipients, transfers, retention, safeguards.
Is collection necessary? Are notices aligned? Is vendor access limited? Are retention rules implemented? Can rights requests be fulfilled?
Validate the contract, assign the owner, restrict exported fields, confirm deletion behaviour, and schedule annual review.
Measures should be based on agreed definitions and baselines. Inventory completeness alone does not prove legal compliance or effective control operation.
A reliable estimate requires scoping because effort depends on organisational complexity, evidence quality, regulatory context, and the required operating model.
Share the approximate number of business units, systems, jurisdictions, existing records, platform needs, and target deliverables.
The delivery approach combines privacy, data governance, technology, assurance, and operating-model considerations while keeping legal and client decision responsibilities explicit.
Records are built from traceable evidence and accountable validation rather than untested assumptions or automated discovery alone.
The inventory can link to data governance, security, risk, retention, vendor management, architecture, and change processes.
Requirements and operating needs are defined before recommending configuration, integration, or platform choices.
Assumptions, missing evidence, unresolved legal questions, exclusions, and responsibility boundaries are documented.
Support can extend from assessment through data migration, workflow configuration, testing, training, reporting, and managed operation.
Templates, field guidance, playbooks, training, and quality calibration help internal teams retain effective ownership.
Discuss current records, regulatory drivers, technology, ownership, evidence, and maintenance requirements with DataConsultant.
Agree access, data minimisation, storage, encryption, transfer, retention, deletion, and confidentiality requirements for engagement evidence.
Use field definitions, mandatory rules, validation, reconciliation, sampling, ownership approval, exception tracking, and review dates.
Avoid unnecessary personal-data collection during discovery and define how sensitive evidence will be handled and removed.
Escalate legal interpretation, regulatory obligations, transfer mechanisms, and risk acceptance to authorised client specialists.
The following testimonials are realistic representative examples written for this service. They are not presented as independently verified client endorsements.
“The team converted fragmented spreadsheets and interview notes into a structured processing inventory with clear ownership. Communication was consistent, quality checks were visible, and revisions were handled carefully without losing the detail our privacy and technology teams needed.”
“We needed more than a compliance register. The engagement connected systems, purposes, vendors, transfers, retention, and risks in a way that supported day-to-day decisions. Delivery was professional, practical, and well coordinated across legal, security, data, and operations.”
“The inventory design gave our business owners clear definitions and a manageable approval workflow. The consultants responded constructively to revision requests, documented limitations, and transferred enough knowledge for our internal team to maintain the records after handover.”
“Data discovery findings had previously been difficult to translate into accountable records. The team reconciled automated outputs with business evidence, resolved duplicates, and created a useful issue register. We were satisfied with the quality, pace, and transparency of delivery.”
“The work clarified how customer and employee data moved through our applications and external providers. Stakeholder communication was organised, sensitive questions were handled professionally, and the final maps supported retention, vendor review, and privacy-impact assessment planning.”
“Our existing records were extensive but inconsistent. DataConsultant introduced practical quality rules, ownership, review dates, and reporting without forcing a tool replacement. The revisions were controlled, delivery remained collaborative, and the final operating model was understandable to business teams.”
A privacy data inventory commonly records processing activities, purposes, data subjects, personal-data categories, sources, collection methods, lawful bases where applicable, systems, owners, recipients, processors, transfers, retention, security measures, privacy risks, evidence, review status, and related controls. The exact fields should match the organisation’s obligations and operating needs.
They overlap but are not always identical. A record of processing activities is a legally defined record in some jurisdictions, while a broader privacy data inventory may include additional system, data-flow, control, risk, evidence, and operational fields. Legal specialists should confirm applicable statutory requirements.
A data catalogue typically focuses on data assets, metadata, lineage, definitions, and discovery. A privacy inventory focuses on personal-data processing, purposes, data subjects, lawful authority, recipients, transfers, retention, ownership, and privacy controls. The two can be integrated so technical metadata supports privacy records.
Automated discovery can locate and classify likely personal data, but it generally cannot establish business purpose, legal context, accountability, recipient relationships, retention rationale, or whether a processing activity is accurately described. Human validation and governance remain necessary.
There is no dependable fixed duration without discovery. Timing depends on scope, jurisdictions, business units, systems, vendors, processing complexity, evidence quality, stakeholder availability, validation cycles, technology implementation, and whether the work includes data-flow mapping or remediation.
Useful inputs include existing inventories, policies, notices, retention schedules, system and vendor lists, architecture diagrams, contracts, data-flow documentation, impact assessments, audit findings, security information, organisational structures, and access to accountable business, privacy, legal, data, technology, and risk stakeholders.
Maintenance commonly combines periodic review with event-driven triggers such as new products, systems, vendors, integrations, purposes, data categories, transfers, retention changes, incidents, or acquisitions. Clear ownership, approval workflow, reminders, reporting, and assurance checks are required.
Privacy or compliance may own the framework, but reliable records require distributed accountability. Business-process owners, product owners, system owners, data owners, procurement, security, architecture, legal, risk, and vendor managers may each supply, approve, or maintain relevant information.
Yes. A well-linked inventory can help identify likely systems, data stores, owners, recipients, processors, retention rules, and dependencies. It does not itself execute identity verification, legal assessment, data retrieval, redaction, or response approval unless those activities are separately scoped.
Platform support can include requirements, data-model design, taxonomy, workflow, roles, data migration, integrations, reporting, testing, training, and operating procedures. Capability depends on the selected platform, access, vendor arrangements, technical environment, and agreed scope.
Pricing is influenced by organisational scope, systems, processing activities, countries, vendors, evidence quality, mapping depth, workshops, validation cycles, platform work, integration, migration, training, reporting, and managed-service requirements. A written estimate can be provided after initial scoping.
No. An inventory improves visibility and accountability but does not by itself prove that processing is lawful, notices are adequate, controls operate effectively, contracts are sufficient, transfers are valid, or rights are fulfilled. Compliance conclusions require appropriate legal, control, and assurance review.
Yes. The engagement can coordinate with internal or external legal counsel, privacy officers, security teams, platform vendors, systems integrators, auditors, and managed-service providers. Decision rights, confidentiality, access, dependencies, and responsibility boundaries should be agreed at the outset.
Missing evidence, conflicting statements, uncertain ownership, and unresolved legal questions should be recorded as limitations or issues. The delivery process can assign owners, evidence requests, escalation routes, target dates, and approval decisions rather than treating uncertain information as confirmed.
Share the current state, business drivers, technology, jurisdictions, and desired outcomes for a practical next-step recommendation.