Terminology Index

Glossary

33 terms starting with "G"

Open concept maps

Showing 1-32 of 33 terms

G
32

GDPR Data Mapping

Building the inventory of personal data flows required for GDPR, what personal data the organization holds, where it comes from, how it is used, and where it goes, as a foundation for the program's GDPR compliance.

Framed within building a security program, GDPR data mapping produces the record of processing the regulation effectively requires: cataloging personal data, its sources, purposes, lawful bases, storage, and transfers. This map underpins nearly every other GDPR obligation, honoring data-subject rights, assessing breach impact, managing transfers, so establishing it is a foundational step in the program's privacy compliance and feeds directly into posture and evidence.

Introduced in: GRC Capstone: Building a Security Program

Examples

  • Cataloging the personal data the organization processes and why.
  • Documenting data flows and transfers for the GDPR record of processing.
  • Using the data map to support data-subject rights and breach assessment.

No related terms linked yet.