Depth 28.2 · Security and compliance readiness · Level 3
Data protection contour
Data protection contour is the engineering side of data protection: knowing what personal data a company holds, where it flows, who can access it, how long it is kept and how it is deleted. It produces the records of processing, data flow maps, retention and deletion rules, access controls and subprocessor lists that a privacy programme depends on. It is not legal drafting; your lawyers write the policies and contracts.
Specification
- Input
- Access to the systems that hold personal data, your supplier list, and any existing privacy documentation.
- Method
- We trace personal data from collection through each system and supplier, record each flow, check access and retention against the rules you have set, and build deletion and access request steps into the systems.
- Deliverable
- Records of processing, a data flow map, a subprocessor list, and retention and deletion rules implemented in the systems.
- Measured by
- Systems covered in the records of processing, records deleted on schedule, and data access requests answered within the period the applicable law sets.
Most often bought inPayments and fintech, B2B software, Professional services, Ecommerce
The artefact, before and after
Records of processing, a data flow map, a subprocessor list, and retention and deletion rules implemented in the systems.
Inside it
- 01Records of processing activities
- 02Data flow mapping
- 03Retention and deletion in the systems
- 04Access control review
- 05Subprocessor list
Typical first engagement
The usual order of a first piece of work. Timing and price are set at scoping, once we have seen the stack.
- 01Data mapYou get: Where personal data enters, where it is stored and who can reach it.
- 02Processor listYou get: Every third party that handles the data, with location and contract status.
- 03Gap listYou get: Differences between the map and your published privacy notice, for your counsel.
Security and compliance readiness
Next in this line
Ask about this part of the stack
Write one question about data protection contour in your own systems. We answer it in writing and name what we would need to see to answer it properly.
A written reply, no call needed.