Start with a specific processing activity
Describe what personal data enters the workflow, whose data it is, why it is used, where it goes and who decides those purposes. A social team may handle creator contact details, customer messages, account access logs and campaign analytics. These activities can have different requirements.
The ICO’s documentation guidance explains records of processing under UK GDPR. EU and UK obligations, exemptions and other jurisdictions require their own assessment. This guide is an operational starting point, not a legal compliance determination.
Record decisions rather than assuming consent solves everything
Document the applicable basis and purpose with the responsible privacy reviewer. Consent is not automatically the right basis for every activity, and a checkbox does not resolve retention, access, transfers or security. Keep the scope precise enough to identify which records a request or incident affects.
Map processors, subprocessors and storage locations. Record retention decisions and how deletion actually propagates through exports, backups and vendors. A deletion request marked complete in one dashboard may leave copies elsewhere.
Evaluate software with a real workflow
A privacy suite, consent-management platform, data-discovery product and rights-request tool solve different problems. Choose the capability your mapped activity needs. Ask a vendor to demonstrate discovery coverage, evidence records, request routing, deletion verification, access controls and exports using representative test data.
Do not award a product a universal GDPR-compliant label. Review its contractual role, security evidence, integration scope and actual handling of the activity. Use current documentation and quotes; a feature list does not prove your configuration meets the applicable obligations.
Run an accountable pilot
Use synthetic data for the initial test. Trace one record through collection, use, disclosure, retention and deletion. Confirm the responsible owner at each transition. Test a correction or access request and capture what the tool can and cannot locate.
The builder creates a concise inventory record. Unknown fields remain explicit review work. It does not select a lawful basis, calculate a legal deadline or certify compliance. Bring the record to the appropriate privacy or legal reviewer before relying on it.
Keep the record current
Review the map when a new vendor, audience, purpose or data flow changes the activity. Retain the evidence behind decisions and a version history. The useful outcome is an accurate operational picture and a process that works, not a high score on a generic compliance checklist.