I love my role as a Fractional Data Protection Officer (DPO) and I always start with this one subject and simple question when working with new clients:
“Can you show me where your personal data goes?
Not where it’s stored. Not which system it’s in. But where it travels from the moment someone gives it to you until the day it’s securely deleted.
Often, the answer is silence or a waffled explanation that basically means they do not accurately know how to answer this question.
I know that’s not because organisations don’t care about protecting personal data. It’s because over time systems evolve, departments grow, new software is introduced and processes change. Before long, nobody has a complete picture of how personal data moves around the organisation. I also remind clients that someone must be accountable for that process and the data that is involved in that process too, so we do need to document this.
Because without this, that’s where the risks begin.
If you don’t understand your data flows, how can you be confident you’re protecting them?
Think about all the places personal data might travel….
A customer completes an online form. The information is transferred into a CRM. A copy is emailed to another department. It gets downloaded into a spreadsheet. It’s shared with a third-party supplier. Another employee prints it. Someone stores another copy in Teams or SharePoint or even in their own personal drives – pet hate of mine, it’s so uncontrollable!
Suddenly, what looked like one record now exists in multiple locations, across different systems, managed by different people and you do not realistically know all these areas of data being stored and your staff do not know what acceptable processing is.
Without mapping those data flows, it’s almost impossible to know exactly where personal data is, who has access to it, how long it’s kept or whether it’s adequately protected. This becomes even more important when something goes wrong.
Imagine one of your systems suffers a cyber-attack or a personal data breach.
One of the first questions you’ll need to answer is:
What personal data has been affected?
Closely followed by: Who could be impacted? What harm could they suffer? Do we need to report this to the Information Commissioner’s Office?
If you don’t understand your data flows, answering those questions becomes incredibly difficult.
Instead of making informed decisions, organisations are left trying to piece together information while responding to a live incident. That uncertainty costs valuable time, increases stress and can make it much harder to assess the risks to individuals accurately. Plus, at the time of an incident its normally frantic and this important information can be lost or pushed down the list of priorities which makes it even more crucial to have this document before any incident occurs.
This is why data flow mapping is about far more than creating a diagram for a compliance folder.
It’s about understanding your organisation.
It’s about identifying unnecessary copies of data, reducing risk, improving efficiency and ensuring everyone knows where personal information is being processed.
It also supports almost every other area of good data protection.
A clear understanding of data flows makes it easier to complete Records of Processing Activities, carry out Data Protection Impact Assessments, respond to Subject Access Requests, manage retention periods, review suppliers and make informed decisions following a personal data breach.
One exercise often unlocks improvements across your entire privacy programme.
Whenever I work with an organisation, I encourage them to start by understanding their data before trying to write new policies or procedures.
Because once you know where your data goes, you can start asking the right questions then making decisions and take action!
Do we really need all these copies? Who actually needs access? Is this the safest way to process this information? Could we reduce the risk?
Data protection isn’t about guessing. It’s about knowing.
And that starts with understanding your data flows.
Author – Irene Coyle, Data Protection Officer, OSP Cyber Academy


