SlideShare a Scribd company logo
1 of 8
Download to read offline
CONFIDENTIAL
WASHINGTON,	D.C.				BEIJING				ATLANTA					BRUSSELS					DENVER DUBAI				DUBLIN				HONG	KONG				LONDON	 			MADRID				MILAN				NEW YORK				PARIS				SAN	FRANCISCO				SINGAPORE				SYDNEY				TOKYO	 TORONTO
Privacy	&	Data	Protection
Data	Mapping	Solutions	– Sample	Slides
June	6,	2016
CONFIDENTIAL©	2016	Promontory	Financial	Group	LLC.		All	rights	reserved. 2
Typical	Data	Lifecycle	Mapping	Questions	
Key data lifecycle categories Key elements of information captured
1. Basic Details • Process or activity to which the system relates
• Ownership of data
• Data subjects to whom thepersonal informationrelates (e.g.,applicants, employees, contractors)
• Data Categories (e.g., basic personal details; healthandwelfare; performance and pay; employmentdetails)
• Specific sensitive or other confidential data types involved (e.g., credit card information, salary, performance
reviews, disability details, diversity information)
2. Data Collection • Source of data (i.e.,where thepersonal information originates prior to being entered intothe system. For example,
data may be generated from a user of thesystem, anemployeeor applicant or provided by a third party.)
• Means of collection (i.e., how the personal informationwas collected, obtained or generatedfor thepurposesof the
system / process. For example, direct input by employee, email receivedanddata manually input to system by user,
or automated feeds from linked systems or databases.)
3. Data Usage & Data Handling • Purpose of processing the personal information
• Key manual datahandlingor automated dataprocessingactivities
• Handling of hard copy documents or files containingpersonal information
• Hosting, testing and system developmentlocations where applicable
4. Data Transfers and Access &
Disclosures
• Internal, external andonward transfers,access or disclosures to personal information
• Disclosures to service providers, vendors, and relevantparties
• Assess locations for the purposes ofidentifyingcross border datatransfers
5. Data Retention & Destruction • Data retention anddestructionprocesses around how personal informationis archived or destroyed
• Retention periods prior to destruction
• Responsibilities of external vendors for the archiving / destruction of personal informationtransferred
6. Security • Scope to includespecific technical andorganizational security considerations whichhavebeen applied. For
example, access controls andrestrictions, use of passwords / encryption
The key questions and considerations below can be used to assess the privacy impactof the data flows identified and can be
instrumental in the developmentofdata maps.
CONFIDENTIAL©	2016	Promontory	Financial	Group	LLC.		All	rights	reserved. 3
Recent	Data	Mapping	Framework	Project
Creation	of	Data	Mapping	Toolkit	
ü Alignment with and cross-reference to business process mapping
ü Provides a detailed record of key processes/activities within theorganisation
ü Aids in the identification of knowledge gaps toprompt further investigation
ü Increases knowledge of data handling practices within the organisation
ü Forms a basis for best practices and regulator standards
• A toolkit of data mapping templates, information gathering and reporting tools,
user guidance and training materials was produced to allow the client to roll out
the data mapping exercise to other areas of its business
• Training workshops and management briefing sessions were run to explain how to
apply the methodology and use the toolkit in order to deploy and maintain the
Data Mapping Framework
• QA managers and related local contacts were assigned responsibility for the
maintenance and updating of the Data Mapping Framework, including periodic
milestones and reporting obligations
Sample	Pilot	Data	Mapping	Exercise
• Interviews were undertaken with stakeholders relevant
to the data lifecycle of the pilot business areas
• A review was made of the existing business process
data maps and QA documentation to align with and
validate data lifecycle practices identified during
information gathering
• Fieldwork also included interviews and documentation
reviews relating to management of key systems and
data lifecycle related technology
• Data Mapping tables, diagrams and reports were refined
during the pilot phase and provided the basis for the
Data Mapping Toolkit templates and guidance
Data	
Lifecycle	
Mapping	
Table
Data	
Lifecycle	
Mapping	
Reports
Data	
Maps	&	
Key	
User	
Guidance
Data	
Types	
Guidance
Data Lifecycle Mapping Framework
CONFIDENTIAL©	2016	Promontory	Financial	Group	LLC.		All	rights	reserved. 4
Overview	of	Outputs	and	Templates	
Key Outputs of the Data Lifecycle Mapping Process Data	
Mapping	
Table	
Data	
Categories,
Subjects
&	Types	
Table		
Special	
Data	Types	
Table	
Data	Map	&	
Key
CONFIDENTIAL©	2016	Promontory	Financial	Group	LLC.		All	rights	reserved. 5
Overview	of	Data	Lifecycle	Mapping	Framework
CONFIDENTIAL©	2016	Promontory	Financial	Group	LLC.		All	rights	reserved. 6
Sample	Overview	Data	Flow	Map
CONFIDENTIAL©	2016	Promontory	Financial	Group	LLC.		All	rights	reserved. 7
Sample	Process	Specific	Data	Lifecycle	Map
CONFIDENTIAL©	2016	Promontory	Financial	Group	LLC.		All	rights	reserved. 8
Contact	Details
Robert	Grosvenor
Director
Promontory	Financial	Group	(UK)	Limited
30	Old	Broad	Street
London
EC2N	1HT
Direct:	+44	(0)20	7997	3407
rgrosvenor@promontory.com
James	Gregoire
Senior	Principal
Promontory	Financial	Group,	LLC
Spear	Tower,	1	Market	Plaza,	Suite	4100
San	Francisco,	CA	94105
Direct:	+1	424-225-1015
jgregoire@promontory.com
Simon	McDougall
Managing	Director
Promontory	Financial	Group	(UK)	Limited
30	Old	Broad	Street
London
EC2N	1HT
Direct:	+44	(0)20	7997	3456
smcdougall@promontory.com
Michael	Spadea
Director
Promontory	Financial	Group,	LLC
Spear	Tower,	1	Market	Plaza,	Suite	4100
San	Francisco,	CA	94105
Direct:	+1	415-905-0254
mspadea@promontory.com

More Related Content

What's hot

Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRIT Governance Ltd
 
Appointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRAppointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRIT Governance Ltd
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
Datum DPO outsourced May 2016
Datum DPO outsourced May 2016Datum DPO outsourced May 2016
Datum DPO outsourced May 2016Mark Honeyball
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPRTripwire
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?Frederick Penaud
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpJason Lackey
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection RegulationRamiro Cid
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016John Greenwood
 
COVID-19: What are the Potential Impacts on Data Privacy?
COVID-19: What are the Potential Impacts on Data Privacy?COVID-19: What are the Potential Impacts on Data Privacy?
COVID-19: What are the Potential Impacts on Data Privacy?TrustArc
 
CyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPRCyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPRIryna Chekanava
 
Assessing Risk: How Organizations Can Proactively Manage Privacy Risk
Assessing Risk: How Organizations Can Proactively Manage Privacy RiskAssessing Risk: How Organizations Can Proactively Manage Privacy Risk
Assessing Risk: How Organizations Can Proactively Manage Privacy RiskTrustArc
 
Data Privacy Program – a customized solution for the new EU General Regulatio...
Data Privacy Program – a customized solution for the new EU General Regulatio...Data Privacy Program – a customized solution for the new EU General Regulatio...
Data Privacy Program – a customized solution for the new EU General Regulatio...IAB Bulgaria
 
CyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPRCyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPRShadi A. Razak
 

What's hot (19)

Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPR
 
Appointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRAppointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPR
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Datum DPO outsourced May 2016
Datum DPO outsourced May 2016Datum DPO outsourced May 2016
Datum DPO outsourced May 2016
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPR
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can Help
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 
COVID-19: What are the Potential Impacts on Data Privacy?
COVID-19: What are the Potential Impacts on Data Privacy?COVID-19: What are the Potential Impacts on Data Privacy?
COVID-19: What are the Potential Impacts on Data Privacy?
 
CyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPRCyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPR
 
Assessing Risk: How Organizations Can Proactively Manage Privacy Risk
Assessing Risk: How Organizations Can Proactively Manage Privacy RiskAssessing Risk: How Organizations Can Proactively Manage Privacy Risk
Assessing Risk: How Organizations Can Proactively Manage Privacy Risk
 
Data Privacy Program – a customized solution for the new EU General Regulatio...
Data Privacy Program – a customized solution for the new EU General Regulatio...Data Privacy Program – a customized solution for the new EU General Regulatio...
Data Privacy Program – a customized solution for the new EU General Regulatio...
 
CyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPRCyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPR
 
3GRC approach to GDPR V 0.1 www.3grc.co.uk
3GRC  approach to GDPR V 0.1 www.3grc.co.uk3GRC  approach to GDPR V 0.1 www.3grc.co.uk
3GRC approach to GDPR V 0.1 www.3grc.co.uk
 

Similar to 1211000-792-2-Promontory - Data Mapping Slides 06-06-16

Designing High Quality Data Driven Solutions 110520
Designing High Quality Data Driven Solutions 110520Designing High Quality Data Driven Solutions 110520
Designing High Quality Data Driven Solutions 110520MariaHalstead1
 
Data Ethics Framework 2.pptx
Data Ethics Framework 2.pptxData Ethics Framework 2.pptx
Data Ethics Framework 2.pptxUgurKaplancali
 
Prescriptive Analytics-1.pptx
Prescriptive Analytics-1.pptxPrescriptive Analytics-1.pptx
Prescriptive Analytics-1.pptxKarthik132344
 
Introduction to data science
Introduction to data scienceIntroduction to data science
Introduction to data scienceSpartan60
 
Introduction to Business and Data Analysis Undergraduate.pdf
Introduction to Business and Data Analysis Undergraduate.pdfIntroduction to Business and Data Analysis Undergraduate.pdf
Introduction to Business and Data Analysis Undergraduate.pdfAbdulrahimShaibuIssa
 
Workable Enteprise Data Governance
Workable Enteprise Data GovernanceWorkable Enteprise Data Governance
Workable Enteprise Data GovernanceBhavendra Chavan
 
Cff data governance best practices
Cff data governance best practicesCff data governance best practices
Cff data governance best practicesBeth Fitzpatrick
 
BIG DATA CHAPTER 2 IN DSS.pptx
BIG DATA CHAPTER 2 IN DSS.pptxBIG DATA CHAPTER 2 IN DSS.pptx
BIG DATA CHAPTER 2 IN DSS.pptxmuflehaljarrah
 
TOP_407070357-Data-Governance-Playbook.pptx
TOP_407070357-Data-Governance-Playbook.pptxTOP_407070357-Data-Governance-Playbook.pptx
TOP_407070357-Data-Governance-Playbook.pptxSabrinaLameiras1
 
Modern Analytics And The Future Of Quality And Performance Excellence
Modern Analytics And The Future Of Quality And Performance ExcellenceModern Analytics And The Future Of Quality And Performance Excellence
Modern Analytics And The Future Of Quality And Performance ExcellenceICFAI Business School
 
CCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc SolutionsCCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc SolutionsTrustArc
 
CDMP SLIDE TRAINER .pptx
CDMP SLIDE TRAINER .pptxCDMP SLIDE TRAINER .pptx
CDMP SLIDE TRAINER .pptxssuser65981b
 

Similar to 1211000-792-2-Promontory - Data Mapping Slides 06-06-16 (20)

Designing High Quality Data Driven Solutions 110520
Designing High Quality Data Driven Solutions 110520Designing High Quality Data Driven Solutions 110520
Designing High Quality Data Driven Solutions 110520
 
KIT601 Unit I.pptx
KIT601 Unit I.pptxKIT601 Unit I.pptx
KIT601 Unit I.pptx
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Data Ethics Framework 2.pptx
Data Ethics Framework 2.pptxData Ethics Framework 2.pptx
Data Ethics Framework 2.pptx
 
Prescriptive Analytics-1.pptx
Prescriptive Analytics-1.pptxPrescriptive Analytics-1.pptx
Prescriptive Analytics-1.pptx
 
Introduction to data science
Introduction to data scienceIntroduction to data science
Introduction to data science
 
Introduction to Business and Data Analysis Undergraduate.pdf
Introduction to Business and Data Analysis Undergraduate.pdfIntroduction to Business and Data Analysis Undergraduate.pdf
Introduction to Business and Data Analysis Undergraduate.pdf
 
Workable Enteprise Data Governance
Workable Enteprise Data GovernanceWorkable Enteprise Data Governance
Workable Enteprise Data Governance
 
Cff data governance best practices
Cff data governance best practicesCff data governance best practices
Cff data governance best practices
 
BIG DATA CHAPTER 2 IN DSS.pptx
BIG DATA CHAPTER 2 IN DSS.pptxBIG DATA CHAPTER 2 IN DSS.pptx
BIG DATA CHAPTER 2 IN DSS.pptx
 
TOP_407070357-Data-Governance-Playbook.pptx
TOP_407070357-Data-Governance-Playbook.pptxTOP_407070357-Data-Governance-Playbook.pptx
TOP_407070357-Data-Governance-Playbook.pptx
 
Modern Analytics And The Future Of Quality And Performance Excellence
Modern Analytics And The Future Of Quality And Performance ExcellenceModern Analytics And The Future Of Quality And Performance Excellence
Modern Analytics And The Future Of Quality And Performance Excellence
 
Data Science in Python.pptx
Data Science in Python.pptxData Science in Python.pptx
Data Science in Python.pptx
 
Data mining
Data miningData mining
Data mining
 
Data mining
Data miningData mining
Data mining
 
CCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc SolutionsCCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
 
ii mca juno
ii mca junoii mca juno
ii mca juno
 
Unit 4 Advanced Data Analytics
Unit 4 Advanced Data AnalyticsUnit 4 Advanced Data Analytics
Unit 4 Advanced Data Analytics
 
Data Mining
Data MiningData Mining
Data Mining
 
CDMP SLIDE TRAINER .pptx
CDMP SLIDE TRAINER .pptxCDMP SLIDE TRAINER .pptx
CDMP SLIDE TRAINER .pptx
 

1211000-792-2-Promontory - Data Mapping Slides 06-06-16