Governance and inventory

Link systems, assets and data flows

Identify where personal data is collected, stored, accessed, transferred and deleted, and make each resource traceable to the activities and entities that use it.

A processing activity that names a purpose and a lawful basis but no system is only half described. A supervisory authority asking where the data actually lives needs the activity to point at the customer database, the support ticketing tool and the backup provider by name.

At a professional services firm this typically surfaces during onboarding, when systems already exist in the register from earlier activities and simply need attaching, alongside the measures that protect them.

This proves that a system can be read back to every activity that depends on it, and that a change to the system's risk profile can be traced forward to everything it touches.

Regulation
Articles 5, 25, 30 and 32
Registers
Processing activity · System or asset · Measure · Transfer record
The linked records band of a processing activity.
The linked records band of a processing activity.

The steps

  1. 01Open the activity and expand the Linked records band beneath the header.
  2. 02Read what the record already applies to before choosing anything further.
  3. 03Use "Link a record" to attach the systems that hold the data.
  4. 04Use "Link a record" again to attach the measures that protect those systems.
  5. 05Where the data leaves the European Economic Area, use "Link a record" to attach the transfer record.
  6. 06Open one of the linked systems directly from the band and confirm the activity now appears on its own linked records.
Linking a system. Records that do not fit the relationship are held back and can be revealed.
Linking a system. Records that do not fit the relationship are held back and can be revealed.

Accepted when

  • The linked band states what the record already applies to before anything further is chosen.
  • A system can be read back to every activity that uses it.