The document discusses data flow mapping in relation to the EU GDPR, outlining the regulatory landscape, legal requirements, risk management, and techniques for conducting data flow mapping exercises. It highlights the necessity of GDPR compliance, including conducting Data Protection Impact Assessments (DPIAs) and understanding information flows and related risks. Various methods and challenges of mapping personal data flows within organizations are also detailed to ensure adequate security and compliance with data protection laws.
Data protection model
underthe GDPR
Information Commissioner’s Office (ICO)
(supervising authority)
Data controller
(organisations)
Data subject
(individuals)
Data
processor
Third
countries
Third
parties
Duties
Rights
Disclosure?
Inform?
Security?
Guarantees?
Assessment
Enforcement
European Data Protection Board