
LEGAL GUIDE · PRIVACY
A data-mapping starter for businesses that want accurate privacy documents.
A privacy notice should describe verified processing. Before drafting one, map what data enters the organization, why it is used, where it goes and who can make decisions about it.
Begin with a real activity—a customer account, job application, online order or support request. Follow the information from collection through access, storage, sharing, retention and deletion. The exercise is practical; it is not a request for every database column.
1. Identify the activity and purpose
- Name the business process in plain language.
- Record the people whose data is involved and the categories collected.
- State the operational purpose and which team owns it.
- Separate necessary processing from “nice to have” collection.
2. Trace systems and recipients
List the website, CRM, email platform, cloud drive, payment provider, analytics tool and other systems involved. Record internal access and every vendor or partner that receives the information. If no one knows where a copy is stored, that is a governance issue to resolve—not a blank to hide in the notice.
3. Ask the questions that change legal risk
- Is sensitive, financial, location or children’s data involved?
- Does information cross a border or reach a foreign vendor?
- Is it used for marketing, profiling or an automated decision?
- What contract governs the vendor and what happens after termination?
- How long is the information genuinely needed?
4. Convert the map into actions
Prioritize inaccurate notices, missing processing terms, excessive access, unclear retention and unsupported marketing. Assign an owner and review date to each action. A map that is never maintained becomes another outdated document, so connect updates to procurement, product changes and new marketing tools.
Jurisdiction matters. Applicable obligations depend on the organization, people, contracts and countries involved. This starter is a preparation tool, not a legal conclusion.