4.2 Data Discovery, System Integrations & Keeping the Inventory Current

Key Takeaways

  • Indicator III.A.1 names four mapping duties — data inventories, data flows, data life cycle and system integrations — and system integrations is the one most often skipped.
  • Interview-only discovery finds the systems people remember; automated discovery finds shadow IT, dark data and forgotten copies, so a defensible programme uses both.
  • Integration mapping matters because personal data usually leaves a system through an API, an ETL job, a webhook or a file drop that no system owner considers a disclosure.
  • An inventory is a living artifact: refresh it on defined triggers — new system, new vendor, new purpose, new jurisdiction, M&A, and a scheduled full re-attestation.
  • Inventory quality is measurable through coverage, staleness, attestation rate and the DSAR lookup time it enables — measure those or the inventory decays invisibly.
Last updated: August 2026

The Inventory You Built Last Year Is Already Wrong

Indicator III.A.1 lists four mapping obligations in one line: map data inventories, map data flows, map data life cycle and system integrations. Most programs deliver the first three and quietly drop the fourth, which is where personal data actually moves.

The deeper problem is decay. An inventory is a photograph of a moving organization. Engineering ships a new service, marketing signs a tool on a corporate card, an acquisition adds forty systems, a team stands up an analytics extract "temporarily." Within a year an unmaintained inventory is a document that produces false confidence — worse than none, because decisions are made on it.

Four discovery methods, four blind spots

MethodFindsMisses
Interviews and questionnairesBusiness context, purposes, lawful basis, ownershipSystems nobody remembers; deliberate omissions
Automated data discovery / scanningActual data at rest, including unexpected copies and misclassified storesPurpose and lawful basis; anything outside scanned estates
System-of-record inventories (CMDB, SSO, expense data)Sanctioned applications and, via expense records, unsanctioned onesData content inside them
Network and API telemetryLive flows, including egress nobody documentedHistorical or batch movement outside the capture window

None is sufficient alone, and the exam's credited answer is almost always a combination. Interviews without scanning produce an inventory of what people remember; scanning without interviews produces a list of tables with no purpose or lawful basis attached — and purpose is what makes an inventory legally useful.

Three recurring blind spots deserve naming. Shadow IT is software procured outside IT, best surfaced through expense and SSO logs. Dark data is retained but unused — old exports, abandoned databases, backups of decommissioned systems — carrying full breach and rights-request exposure with zero business value. Endpoint and collaboration sprawl covers the spreadsheets, shared drives and chat exports where sensitive data quietly accumulates.

Integration mapping

For each system, record what enters, what leaves, and how:

Integration typeExampleGovernance question
API (real-time)CRM pushes contacts to the marketing platformWhich fields, what purpose, what lawful basis?
Batch ETLNightly warehouse loadDoes the copy inherit the source retention rule?
Webhook / event streamOrder event to a fulfilment partnerIs the partner a processor with a DPA?
File transferSFTP payroll drop to a benefits providerEncrypted, access-controlled, logged, aged?
Embedded third-party codeAnalytics or advertising tag on a web pageConsent-gated? Does it transmit identifiers?

The last row is disproportionately tested because it is disproportionately litigated: a tag on a checkout page can transmit personal data to a third party continuously without appearing on any system inventory at all.

Keeping it current

A refresh cadence built only on the calendar always lags. Pair a scheduled review with event triggers:

  • New system, vendor or major release entering production
  • New processing purpose for existing data
  • New jurisdiction, market or entity
  • Merger, acquisition or divestiture
  • Post-incident, where the incident revealed an undocumented store
  • Annual full re-attestation by each system owner

Attestation is what makes this stick. Asking each system owner to confirm or correct their records annually converts a privacy-team chore into distributed ownership, and produces a dated record of who confirmed what.

Measuring inventory health

MetricWhat it reveals
Coverage — inventoried systems as a share of the CMDB/SSO populationWhether whole estates are missing
Staleness — records not reviewed within the cadenceSilent decay
Attestation rate — owners who completed the annual confirmationWhether ownership is real
Field completeness — records with lawful basis, retention and recipients populatedWhether the inventory can answer a regulator
DSAR lookup time — hours to locate all data for one individualThe operational payoff, and the honest test

That last metric is the useful one to report upward, because it links inventory quality to an outcome an executive already cares about.

Worked scenario

A company completes a data inventory through interviews and declares the mapping done. Six months later a breach exposes a support-team spreadsheet on a shared drive holding two years of customer identity-verification documents. The inventory was not wrong about the systems it covered; it was incomplete because interviews cannot find what nobody thinks to mention. The credited remediation adds automated discovery across shared drives and endpoints, an integration map covering exports from the support platform, retention rules applied to derived copies, and event-triggered refresh so the next undocumented store surfaces before an attacker finds it.

Test Your Knowledge

A privacy team builds its data inventory entirely through structured interviews with system owners. Which weakness should the privacy manager most expect under indicator III.A.1?

A
B
C
D
Test Your Knowledge

An organization discovers that an advertising tag embedded on its checkout page has been transmitting customer identifiers to a third party for two years. The tag appears on no system inventory. Which III.A.1 mapping obligation was most directly missed?

A
B
C
D