You know the five love languages, right?

❤️ Words of affection ❤️Physical touch ❤️Receiving gifts ❤️Quality time ❤️Acts of service

Well… yes, if you ask me there is a 6th one: DATA MAPPING.

(or maybe it fits in one of the already existing categories? experts, comment below and let me know!)

Why, you ask? It’s a cliché really… Because knowledge is power! And if I’m navigating the digital era, I like feeling powerful and in control, rather than sailing into the unknown with hope as my boat (as we say in Greek 😊). Bear in mind, this is not GDPR or legal compliance, those just come as a bonus – this is about knowing your data and being able to take strategic decisions when your main competitors are struggling in the chaos of data governance… To put it simply, if you don’t understand your data flows, everything else is guesswork: policies, risk assessments, even innovation.

If you look at article 30 paragraph 5 of the GDPR, it already provides an exemption to the obligation of maintaining a record of processing activities. You don’t need to document your processes if you have fewer than 250 employees and all of the below apply cumulatively:

  • the processing is ONLY occasional,
  • the processing does not entail a risk to the rights and freedoms of data subjects, and
  • the processing does not involve special categories of data (art.9.1) or personal data relating to criminal convictions or offences (aka Sensitive Processing).

Is that ever the case? Can we safely say that smaller organizations do not need to data map? And what about groups of companies, where techincally an entity may have a lot fewer than 250 employees but all the entities together, usually handled by the same internal services, have a lot more? Thankfully, WP29 already in 2018 cleared the atmosphere, taking a restrictive position and explaining that the derrogation is not absolute and the occurence of any criterion alone triggers the obligation to maintain a record.

My take on this? Even if you somehow find yourself matching all the criteria (and I can help you out with that), map away anyway!

The cost? Minimal, from a couple man hours to maximum 100 man hours per year if you are a large organisation. Aaand maybe a few unhappy faces of the people who will have to keep it up to date and don’t necessarily understand why (although once they get the hang of it, it’s really not that complicated)….

The benefit? Huuuge. At this stage, if you look at any new piece of law that comes out, not only in the EU but globally, the number one thing you have to do is KNOW YOUR DATA. In the old world, land and ledgers defined power. Today, it’s data and those who understand its flows:

  1. You know what could hurt you before it does. Reputation is everything and surprises are expensive.
  2. You make faster, better decisions. Your projects don’t stall in legal/compliance limbo – use your DPO as the basis, the exercise is done, your map is already there every single time, your teams don’t need to reinvent the wheel whenever they want to implement something new (wink wink GenAI).
  3. You reduce costs without cutting value. Most companies collect too much data, store it for too long, spend a fortune in protecting data they don’t even need. Wanna try to put a number on this on the admin side?
  4. You stay in control during growth or crisis. Whether it’s a breach, a regulator knocking on your door, an acquisition, a sudden AI initiative, if you know your data you stay calm, if not you scramble. Control is a competitive advantage.
  5. You build trust internally and externally. Customers, partners, and of course regulators trust companies that can answer simple questions clearly and don’t lose their sh… when asked “so…where does your data go?”

If you don’t understand your data, you don’t fully understand your business. As simple as that.

Data mapping isn’t about compliance, it’s about running your company with eyes open.


0 Comments

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *