4.2 Data Discovery, System Integrations & Keeping the Inventory Current
Key Takeaways
- Indicator III.A.1 names four mapping duties — data inventories, data flows, data life cycle and system integrations — and system integrations is the one most often skipped.
- Interview-only discovery finds the systems people remember; automated discovery finds shadow IT, dark data and forgotten copies, so a defensible programme uses both.
- Integration mapping matters because personal data usually leaves a system through an API, an ETL job, a webhook or a file drop that no system owner considers a disclosure.
- An inventory is a living artifact: refresh it on defined triggers — new system, new vendor, new purpose, new jurisdiction, M&A, and a scheduled full re-attestation.
- Inventory quality is measurable through coverage, staleness, attestation rate and the DSAR lookup time it enables — measure those or the inventory decays invisibly.
The Inventory You Built Last Year Is Already Wrong
Indicator III.A.1 lists four mapping obligations in one line: map data inventories, map data flows, map data life cycle and system integrations. Most programs deliver the first three and quietly drop the fourth, which is where personal data actually moves.
The deeper problem is decay. An inventory is a photograph of a moving organization. Engineering ships a new service, marketing signs a tool on a corporate card, an acquisition adds forty systems, a team stands up an analytics extract "temporarily." Within a year an unmaintained inventory is a document that produces false confidence — worse than none, because decisions are made on it.
Four discovery methods, four blind spots
| Method | Finds | Misses |
|---|---|---|
| Interviews and questionnaires | Business context, purposes, lawful basis, ownership | Systems nobody remembers; deliberate omissions |
| Automated data discovery / scanning | Actual data at rest, including unexpected copies and misclassified stores | Purpose and lawful basis; anything outside scanned estates |
| System-of-record inventories (CMDB, SSO, expense data) | Sanctioned applications and, via expense records, unsanctioned ones | Data content inside them |
| Network and API telemetry | Live flows, including egress nobody documented | Historical or batch movement outside the capture window |
None is sufficient alone, and the exam's credited answer is almost always a combination. Interviews without scanning produce an inventory of what people remember; scanning without interviews produces a list of tables with no purpose or lawful basis attached — and purpose is what makes an inventory legally useful.
Three recurring blind spots deserve naming. Shadow IT is software procured outside IT, best surfaced through expense and SSO logs. Dark data is retained but unused — old exports, abandoned databases, backups of decommissioned systems — carrying full breach and rights-request exposure with zero business value. Endpoint and collaboration sprawl covers the spreadsheets, shared drives and chat exports where sensitive data quietly accumulates.
Integration mapping
For each system, record what enters, what leaves, and how:
| Integration type | Example | Governance question |
|---|---|---|
| API (real-time) | CRM pushes contacts to the marketing platform | Which fields, what purpose, what lawful basis? |
| Batch ETL | Nightly warehouse load | Does the copy inherit the source retention rule? |
| Webhook / event stream | Order event to a fulfilment partner | Is the partner a processor with a DPA? |
| File transfer | SFTP payroll drop to a benefits provider | Encrypted, access-controlled, logged, aged? |
| Embedded third-party code | Analytics or advertising tag on a web page | Consent-gated? Does it transmit identifiers? |
The last row is disproportionately tested because it is disproportionately litigated: a tag on a checkout page can transmit personal data to a third party continuously without appearing on any system inventory at all.
Keeping it current
A refresh cadence built only on the calendar always lags. Pair a scheduled review with event triggers:
- New system, vendor or major release entering production
- New processing purpose for existing data
- New jurisdiction, market or entity
- Merger, acquisition or divestiture
- Post-incident, where the incident revealed an undocumented store
- Annual full re-attestation by each system owner
Attestation is what makes this stick. Asking each system owner to confirm or correct their records annually converts a privacy-team chore into distributed ownership, and produces a dated record of who confirmed what.
Measuring inventory health
| Metric | What it reveals |
|---|---|
| Coverage — inventoried systems as a share of the CMDB/SSO population | Whether whole estates are missing |
| Staleness — records not reviewed within the cadence | Silent decay |
| Attestation rate — owners who completed the annual confirmation | Whether ownership is real |
| Field completeness — records with lawful basis, retention and recipients populated | Whether the inventory can answer a regulator |
| DSAR lookup time — hours to locate all data for one individual | The operational payoff, and the honest test |
That last metric is the useful one to report upward, because it links inventory quality to an outcome an executive already cares about.
Worked scenario
A company completes a data inventory through interviews and declares the mapping done. Six months later a breach exposes a support-team spreadsheet on a shared drive holding two years of customer identity-verification documents. The inventory was not wrong about the systems it covered; it was incomplete because interviews cannot find what nobody thinks to mention. The credited remediation adds automated discovery across shared drives and endpoints, an integration map covering exports from the support platform, retention rules applied to derived copies, and event-triggered refresh so the next undocumented store surfaces before an attacker finds it.
A privacy team builds its data inventory entirely through structured interviews with system owners. Which weakness should the privacy manager most expect under indicator III.A.1?
An organization discovers that an advertising tag embedded on its checkout page has been transmitting customer identifiers to a third party for two years. The tag appears on no system inventory. Which III.A.1 mapping obligation was most directly missed?