Where does personal data live in our organisation?
Short answer: Start with one row per system
Usually in more places than anyone expects: core systems, email, shared drives, laptops, vendor systems, backups, test copies, spreadsheets and paper. A simple inventory, one row per system, is the base for every other duty.
What the law says
Every duty in Sections 5 to 12 assumes you know where the data is. Rule 6 needs safeguards for each system, and Section 11 needs you to find the data when someone asks.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Sections 11–14 · Rule 14: People can ask for a summary of their data and who it was shared with, ask for correction, completion, updating or erasure, complain, and nominate someone to act for them. You must publish how to do this.
Section 8(7) · Rule 8: Erase personal data when its purpose is over or consent is withdrawn, unless a law requires you to keep it, and have your processors erase it too. Rule 8(3) asks every Data Fiduciary to keep personal data, traffic data and logs for at least one year for purposes listed in the Rules.
Steps
List systems, then shared drives, email, spreadsheets and paper stores.
For each one, note whose data, which items, purpose, owner, hosting location and vendors.
CIO / IT head: Start from your application list and cloud bills. Each system needs an owner, a hosting location and a list of the vendors that touch it.
IT department: IT holds the system list. Add personal-data columns to it rather than starting a separate spreadsheet.
What a good answer from management sounds like
“We have an inventory of systems holding personal data, each with an owner, and it was confirmed this quarter.” Effort and time: Medium · 4 to 10 weeks.