Depth 28.2 · Security and compliance readiness · Level 3

Data protection contour

Data protection contour is the engineering side of data protection: knowing what personal data a company holds, where it flows, who can access it, how long it is kept and how it is deleted. It produces the records of processing, data flow maps, retention and deletion rules, access controls and subprocessor lists that a privacy programme depends on. It is not legal drafting; your lawyers write the policies and contracts.

Specification

Input
Access to the systems that hold personal data, your supplier list, and any existing privacy documentation.
Method
We trace personal data from collection through each system and supplier, record each flow, check access and retention against the rules you have set, and build deletion and access request steps into the systems.
Deliverable
Records of processing, a data flow map, a subprocessor list, and retention and deletion rules implemented in the systems.
Measured by
Systems covered in the records of processing, records deleted on schedule, and data access requests answered within the period the applicable law sets.

Most often bought inPayments and fintech, B2B software, Professional services, Ecommerce

The artefact, before and after

Records of processing, a data flow map, a subprocessor list, and retention and deletion rules implemented in the systems.

Before: a blank data protection contour record with a row for each of records of processing activities, data flow mapping, retention and deletion in the systems, access control review, subprocessor list, and no entries. After: every row carries a finding and a checked status, which is the state the work hands over.

Inside it

  • 01Records of processing activities
  • 02Data flow mapping
  • 03Retention and deletion in the systems
  • 04Access control review
  • 05Subprocessor list

Typical first engagement

The usual order of a first piece of work. Timing and price are set at scoping, once we have seen the stack.

  1. 01Data mapYou get: Where personal data enters, where it is stored and who can reach it.
  2. 02Processor listYou get: Every third party that handles the data, with location and contract status.
  3. 03Gap listYou get: Differences between the map and your published privacy notice, for your counsel.

Security and compliance readiness

Next in this line

Ask about this part of the stack

Write one question about data protection contour in your own systems. We answer it in writing and name what we would need to see to answer it properly.

Send one question

A written reply, no call needed.