4.1 Data Inventory, Classification, and Records of Processing
Key Takeaways
- IAPP CIPP/US BoK 2.6.1 I.C PI1 requires knowing data inventory and data classification as core personal-information controls; Domain I.C is 18–22 of the exam's 90 questions.
- A usable inventory captures, at minimum, the data element or category, purpose, lawful or organizational basis, owner, location, retention, and sharing or recipients.
- Classification schemes (public / internal / confidential / restricted) are operational labels; California sensitive personal information is a statutory list in Cal. Civ. Code § 1798.140(ae), including neural data and citizenship or immigration status.
- The inventory is the input to risk assessments, DPIA-style reviews, CCPA category notices, consumer-request scoping, and vendor due diligence — not a filing cabinet trophy.
- Exam trap: a two-year-old spreadsheet is not an inventory. Inventory is a living control that must be updated when systems, vendors, purposes, or locations change.
4.1 Data Inventory, Classification, and Records of Processing
IAPP CIPP/US Body of Knowledge 2.6.1 (effective 1 September 2025) makes information management the largest slice of Domain I. Competency I.C is 18–22 questions inside Domain I's 27–33. The first performance indicator is concrete: know the practices and controls for managing personal information, including data inventory and data classification. Later I.C items on notices, assessments, vendors, and transfers all assume you can find the data. If you cannot name what you hold, where it lives, why you have it, and who else sees it, you cannot run a U.S. privacy program.
The United States has no single federal statute that copies GDPR Article 30's record of processing activities (RoPA). That is not a free pass. Sectoral rules, state comprehensive privacy laws, and Federal Trade Commission (FTC) reasonableness all presuppose that you know your processing. California's California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA) and later bills through Stats. 2025, Ch. 67 (AB 1170) (effective 1 January 2026), requires a business to disclose categories of personal information (PI), purposes, sources, and third parties. You cannot populate those disclosures from memory. You populate them from an inventory.
What a PI inventory must capture
Treat the inventory as the master index of processing, not as a server list. A CIPP/US-ready record, for each processing activity or data store, captures at least these fields:
| Field | What to record | Why the exam cares |
|---|---|---|
| Data element or category | The actual field (email, precise geolocation, Social Security number) or the CCPA category (identifiers, commercial information, sensitive personal information) | Notices, deletion, and access requests are category- and element-specific |
| Purpose | The operational reason collected and each later use | Purpose limitation and "compatible use" questions live here |
| Lawful or organizational basis | In the United States: notice-and-choice, consent where required, contract, employment, legal obligation, or a documented business purpose under Cal. Civ. Code § 1798.140(e) — not a pasted GDPR Article 6 label unless GDPR actually applies | U.S. exams punish candidates who invent a missing federal "legitimate interest" statute |
| Owner | The business process owner and the system owner | Accountability without a GDPR-style data protection officer (DPO) still needs a named human |
| Location | System, cloud region, paper archive, vendor tenant, laptop, backup | Location drives security, transfer, and breach-scope analysis |
| Retention | Trigger and period, plus disposal method | State laws and the FTC both treat indefinite hoarding as a risk |
| Sharing / recipients | Internal teams, service providers, contractors, third parties, affiliates, and government demand channels | This field is how you later decide sale, share, and vendor scope |
Optional but high-value columns include volume, lawful age of the data subject, encryption state, whether the element is sensitive personal information, the source (consumer, employer, data broker, observed), and the authority that governs it (Health Insurance Portability and Accountability Act of 1996 (HIPAA), Gramm-Leach-Bliley Act (GLBA), Children's Online Privacy Protection Act (COPPA), CCPA, or a sister state law).
A record of processing in a multinational is often the same workbook with extra GDPR columns (legal basis, transfer tool, data protection impact assessment (DPIA) status). Do not tell the exam that every U.S. retailer must keep an Article 30 RoPA. Do tell the exam that a U.S. company that is a GDPR controller or processor does need that record for its EU processing, and that a U.S.-only company still needs an inventory to honor state notices, consumer rights, and assessments.
Classification schemes versus statutory sensitive PI
Classification is an internal control language. A common four-tier scheme is:
| Label | Typical content | Handling implication |
|---|---|---|
| Public | Press releases, published privacy notice, store-locator addresses | No confidentiality control beyond integrity |
| Internal | Ordinary employee directories, non-sensitive operational metrics | Need-to-know inside the company |
| Confidential | Customer account files, order history, ordinary contact data | Access control, logging, contractual limits on vendors |
| Restricted | Secrets, credentials, payment data, health or children's data, government identifiers | Least privilege, encryption, heightened monitoring, shorter retention |
Those labels are not statutes. Sensitive personal information under Cal. Civ. Code § 1798.140(ae) is a defined list. As of the 1 January 2026 text it includes PI that reveals a Social Security, driver's license, state identification, or passport number; account log-in or financial-account number in combination with a credential that allows access; precise geolocation (a device-derived location inside a circle of radius 1,850 feet); racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, or union membership; contents of mail, email, or text messages unless the business is the intended recipient; genetic data; and neural data — information generated by measuring central or peripheral nervous-system activity that is not inferred from nonneural information. It also includes biometric processing to uniquely identify a consumer, and PI collected and analyzed concerning health, sex life, or sexual orientation. Publicly available information in the statutory sense is carved out.
Other comprehensive state laws use their own sensitive data lists (often including children's data, precise location, and account credentials). HIPAA protected health information (PHI), GLBA nonpublic personal information (NPI), and COPPA personal information of a child under 13 are sectoral overlays. A Social Security number can be restricted in the classification scheme, sensitive PI under the CCPA, and NPI if a GLBA financial institution holds it. The exam wants you to stack those labels, not pick one and ignore the others.
Worked classification. A fitness app stores (1) a public blog post, (2) a customer email used only to ship a water bottle, (3) a hashed password plus account number, and (4) a consumer's neural-headset stream. (1) is public. (2) is confidential customer PI. (3) is restricted and California sensitive PI because it is an account log-in in combination with a credential. (4) is restricted and California sensitive PI as neural data. Calling all four "internal" fails both the operational scheme and the statute.
How inventory feeds assessments and vendor scoping
A data protection impact assessment in GDPR language, or a data protection assessment / risk assessment in U.S. state language, is only as good as the inventory behind it. You cannot assess the risk of selling precise geolocation if the inventory still says the company "does not collect location." You cannot decide whether a new model-training use is a new purpose if the inventory never recorded the original purpose.
The California Privacy Protection Agency (CPPA) risk-assessment, cybersecurity-audit, and automated decisionmaking technology (ADMT) regulations were approved by the Office of Administrative Law on 22 September 2025 and are effective 1 January 2026. Covered businesses must begin performing required risk assessments for in-scope processing on that date; the first assessment submissions to the CPPA are due 1 April 2028 for assessments conducted in 2026 and 2027. Sister state laws (Colorado, Virginia, Connecticut, Texas, and others) already required assessments for targeted advertising, sale, sensitive-data processing, or certain profiling. Every one of those assessments starts with "what PI, for what purpose, shared with whom."
Vendor scoping uses the same feed. If the inventory lists a cloud bucket of customer exports that marketing emails to a freelancer, that freelancer is in scope for a data processing agreement, security review, and CCPA role analysis. If the inventory is silent, the freelancer is an invisible third party. FTC Start with Security guidance and the GMR Transcription matter teach the same lesson from the security side: you cannot supervise a service provider you have not identified.
Exam trap: inventory is not a one-time spreadsheet
The most reliable I.C trap is the finished workbook. A privacy analyst runs a three-week discovery project, exports a spreadsheet, stores it on a shared drive, and declares the company "inventoried." Two years later the company has migrated to a new customer-relationship platform, hired an ad-tech tag manager, stood up a data lake in a second cloud region, and bought a lookalike file from a broker. The spreadsheet still says "on-premises CRM, no advertising partners." That artifact is evidence of a stale control, not of compliance.
A living inventory has a refresh trigger: new system, new vendor, new purpose, new location, merger, or a material product change. It has an owner. It is reconciled to the privacy notice, to the records-retention schedule, and to the vendor register. It is used, not archived.
Worked scenario. A national retailer prepares its first CCPA notice. Legal drafts categories from last year's marketing slide. During a tabletop, security reveals that store Wi-Fi logs MAC addresses, the loyalty app collects precise geolocation inside the 1,850-foot definition, and a vendor receives nightly customer extracts to train a recommendation model. None of those elements are in the spreadsheet. The correct move is to update the inventory first, reclassify location and any credentials as sensitive where the statute says so, then rewrite the notice, the retention schedule, the vendor contract, and the risk assessment. Publishing the old notice and calling the spreadsheet "done" is the failure mode the exam is written to catch.
A privacy lead is building the company's first personal-information inventory so the firm can support CCPA category notices, consumer requests, and vendor scoping. Which set of fields matches what that inventory must capture?
A wearable-device company stores measurements of a California consumer's central-nervous-system activity that are not inferred from nonneural signals. How should that element be treated under the CCPA as amended through 1 January 2026?
Counsel finds a two-year-old spreadsheet titled "PI inventory" that has not been updated since a cloud migration and a new ad-tech integration. What is the exam-correct evaluation?