Data mapping

Data mapping (finding out what personal data your organisation processes) is often cited as one of the first tasks to tackle in a data protection compliance plan.

Assimilated Regulation (EU) 2016/679, the UK General Data Protection Regulation (UK GDPR) requires data controllers and processors to have a written record of data processing activities, although in certain circumstances, an exception applies for organisations with fewer than 250 employees—see Practice Note: How to undertake data mapping—Legal requirement under the UK GDPR.

The records must be made available to the supervisory authority (the Information Commissioner’s Office) on request.

Data mapping can be an enormous and time-consuming task. Despite the challenges,...

To view the latest version of this document and thousands of others like it, sign-in with LexisNexis or register for a free trial.

Powered by Lexis+®
Latest Practice Compliance News
View Practice Compliance by content type :

Popular documents