Evidence-led
Findings are tied to available records, configurations, metadata, interviews and approved technical observations.
Identify where personal data actually lives, how it moves, who can access it, why it is processed, where copies accumulate and which evidence or control gaps deserve priority. The assessment is designed to turn fragmented inventories and technical signals into an evidence-backed remediation view.
Assessment scope, technical access, evidence handling, jurisdictions, deliverables, timeline and commercial terms are agreed before work begins. This service is not legal advice, statutory audit or certification.
Findings are tied to available records, configurations, metadata, interviews and approved technical observations.
Scope moves beyond policy documents to the locations, copies, flows and processing context of personal data.
Privacy, security, identity, lifecycle, supplier and monitoring evidence is considered where relevant to a finding.
Outputs are organised to support prioritisation, ownership, follow-up investigation and implementation planning.
Privacy inventories often describe intended processing while the technology estate contains historical copies, exports, derived fields, backups, shadow stores and integrations that are harder to see. The assessment tests that gap between documented understanding and observable evidence.
Data exists in file shares, SaaS tools, exports, local stores, test environments or legacy platforms that are not represented in the current inventory.
Source-to-target movement, onward sharing, APIs, extracts, integrations and third-party hand-offs are difficult to trace end to end.
Primary records may be governed while backups, archives, exports, logs and downstream replicas follow different or undocumented lifecycle practices.
Technical owners know the system, business owners know the purpose, and privacy or security teams hold policy context, but evidence is fragmented across functions.
Broad roles, service accounts, privileged access, shared folders or inherited permissions can make it hard to show who can reach personal data and why.
Feature stores, notebooks, extracts, prompt context, training or evaluation data and derived attributes can introduce personal-data copies outside traditional application inventories.
Start with the systems, business processes, jurisdictions and evidence gaps creating the most uncertainty. The assessment can be scoped around a priority domain or a broader enterprise landscape.
Personal data discovery combines business and technical evidence to build a more defensible view of personal-data locations, categories, processing context and control conditions. It can examine metadata, schemas, inventories, data-flow records, access information, approved samples, discovery-tool output and stakeholder evidence across the agreed scope.
The objective is not to create a larger spreadsheet. It is to identify where the organisation lacks reliable visibility, where observed data handling conflicts with intended controls, which findings matter most, who should own them and what should happen next.
The final scope is tailored to the decision, risk and evidence available. These domains show the typical lenses used to turn discovery observations into enterprise-ready findings.
Identify likely personal-data locations across approved applications, platforms and repositories.
Relate discovered elements to personal-data categories, identifiers, sensitive attributes and business meaning.
Trace collection, transformation, replication, interfaces, sharing and downstream use where evidence supports it.
Connect discovered data to business purpose, processing activity, accountable owner and operational responsibility.
Review available evidence for roles, privileged access, service identities and access pathways around material stores.
Compare intended retention and disposal practices with observed copies, archives, backups and downstream stores.
Consider relevant security, classification, logging, monitoring and handling controls around discovered data.
Link observations to evidence, uncertainty, affected systems, owners, control gaps and practical next actions.
A useful assessment follows personal data across the enterprise rather than treating each repository as an isolated scan target. The architecture below illustrates the kinds of locations and cross-cutting controls that can form the assessment boundary.
Define the priority systems and evidence sources first, then connect discovery observations to ownership, processing context, controls and remediation instead of producing an unqualified list of matches.
The engagement can start with imperfect evidence. Missing or conflicting evidence is recorded as a limitation or finding rather than silently replaced with assumptions.
Application inventories, database lists, cloud accounts, storage locations, SaaS systems, architecture diagrams, interfaces and data-platform catalogues.
Processing records, data-flow diagrams, business process maps, collection points, recipient categories, vendors, transfers and downstream uses.
Identity roles, privileged-access records, classifications, retention schedules, deletion procedures, monitoring, DLP or discovery outputs and exceptions.
Data or system owners, privacy and security policies, audit issues, incidents, risk registers, third-party responsibilities and approved legal or compliance interpretations.
| Assessment question | Evidence commonly reviewed | Potential finding type | Decision supported |
|---|---|---|---|
| Where does personal data exist? | Inventories, metadata, schemas, approved scans, file indexes, cloud stores | Unregistered store, unknown copy, incomplete inventory | Inventory correction and discovery priority |
| Why is it processed? | Processing records, process maps, owner interviews, product requirements | Unclear purpose, unsupported reuse, missing owner | Purpose validation and accountability |
| Who can access it? | Role models, groups, service identities, privileged-access evidence | Broad access, inherited permissions, weak review evidence | Access remediation and ownership |
| Where does it move? | Interfaces, APIs, ETL, exports, vendor records, data-flow diagrams | Unknown recipient, undocumented transfer, unmanaged export | Flow mapping and supplier review |
| How long is it retained? | Retention schedules, archive rules, backup policies, delete jobs | Over-retention, inconsistent lifecycle, untested deletion | Retention and disposal action |
| Can the finding be evidenced? | Tickets, approvals, logs, configuration, test records, accountable sign-off | Policy-to-operation evidence gap | Assurance and remediation planning |
Regulatory references are used only when relevant to the organisation, jurisdiction and processing context. The assessment structures evidence and control questions; it does not replace authorised legal interpretation.
The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 have staged commencement. Where India is in scope, assessment criteria should be checked against the provisions in force on the review date and the organisation's approved legal interpretation.
MeitY DPDP Rules & timeline ↗GDPR Article 5 principles such as purpose limitation, data minimisation and storage limitation, together with Article 30 processing-record expectations, can inform discovery evidence for organisations subject to the Regulation.
EUR-Lex GDPR text ↗ISO/IEC 27701:2025 can provide a current privacy information management reference point for organisations managing personally identifiable information. Use as a benchmark does not imply certification.
ISO/IEC 27701:2025 ↗A structured assessment sequence reduces uncontrolled scanning, protects sensitive evidence and keeps technical observations connected to accountable business and control decisions.
Objectives, systems, business units, jurisdictions, exclusions and decision needs.
Access, handling, minimisation, evidence storage and escalation rules.
Inventories, flows, policies, roles, retention, suppliers and existing findings.
Review approved metadata, repositories, schemas, tool output and samples.
Connect likely personal data to category, sensitivity and business context.
Map purpose, ownership, access, movement, sharing and lifecycle where supportable.
Identify evidence-backed gaps, exposure conditions and contributing causes.
Organise remediation by risk, impact, dependency, feasibility and owner.
Review findings, limitations, actions and executive decisions with stakeholders.
Severity is not a hidden proprietary score. The engagement agrees a qualitative prioritisation approach based on evidence and the organisation's risk context, then records the rationale for material findings.
Material findings, decisions, limitations, priorities and recommended next steps.
Validated in-scope stores, observed personal-data signals and evidence references.
Documented source, movement, recipient and third-party relationships where supportable.
Accountability, role, privileged-access and access-evidence observations.
Retention, deletion, archive, backup and copy-management observations.
Relevant privacy and security controls mapped to evidence and identified gaps.
Finding rationale, affected assets, evidence, severity, owner and action status.
Prioritised actions, dependencies, responsible teams and validation needs.
Recommended verification evidence and closure criteria for selected findings.
Decision-focused presentation of findings, priorities, dependencies and next actions.
Use evidence, ownership and dependency information to separate immediate exposure reduction from longer-term inventory, access, retention, governance and platform improvements.
DataConsultant does not publish a fixed fee for this service. Each model is scoped around systems, evidence, jurisdictions, stakeholder access and expected outputs. Timeline and commercial terms are confirmed in the proposal.
For a defined application, data platform, business process or high-risk repository where personal-data visibility needs to be validated.
For organisations that need cross-platform visibility across multiple applications, data stores, files, integrations and accountable teams.
For larger estates that need discovery phased by business unit, geography, data domain, platform or regulatory priority.
For teams that need assessment findings translated into backlog items, control improvements, evidence requirements and selected retesting.
For changing environments where new systems, vendors, data products or AI use cases require periodic discovery and evidence refresh.
Scope-led pricing: a reliable quote depends on the number and type of systems, structured and unstructured repositories, data volumes, existing discovery tooling, access constraints, business units, jurisdictions, stakeholder interviews, third parties, evidence quality, technical review depth, deliverables, onsite needs and whether remediation or retesting is included. No fixed turnaround is stated because the timeline depends on the same factors.
A precise estimate follows a short scoping discussion. These factors determine how much evidence needs to be gathered, how technical the review must be and how many stakeholders need to validate findings.
Discovery technology can surface patterns, but enterprise decisions also need ownership, purpose, lifecycle, access, evidence and remediation context. The engagement is structured around that broader decision need.
Separate observed facts, stakeholder evidence, tool signals, assumptions and unresolved limitations so decision-makers can see what supports each material finding.
Connect data stores and movement with processing purpose, accountable owners, access, suppliers, lifecycle and control responsibilities.
Distinguish consulting findings from legal interpretation, client decisions, implementation ownership, formal assurance and residual-risk acceptance.
Translate visibility gaps into actions that can be assigned, sequenced and verified rather than ending with a catalogue of technical matches.
Use the evidence available in the client estate without making a platform purchase a prerequisite or treating any one discovery product as the control model.
Structure findings, inventories, ownership and control evidence so follow-on privacy governance, retention, access and assurance work can reuse the output.
Share the priority systems, business processes, privacy programme, known findings and evidence constraints. DataConsultant can shape a focused assessment boundary and a practical next step.
Answers to common buyer questions about scope, evidence, production access, deliverables, regulation, prioritisation, pricing, timeline and follow-on work.
Share your contact details and requirement. DataConsultant can review the likely assessment boundary, evidence needs, stakeholder involvement and appropriate next step.