Data Inventory and Mapping
A data inventory is a catalog of the data an organization holds—what it collects, where it is stored, how it is used, and who has access to it. Data mapping builds on that inventory by tracing how data moves through and between systems, including how it is stored and shared. Together, these practices give an organization a clear picture of its data assets, which supports privacy and security programs and can help demonstrate compliance obligations under regimes such as the GDPR and CCPA.
Data inventory and mapping are complementary data-governance processes. A data inventory (sometimes termed a record of authority) is a structured catalog of an organization's data assets that identifies data—particularly personally identifiable data—across systems, websites, and repositories, capturing attributes such as data type, storage location, usage, and access. Data mapping documents the flows and relationships of that data, including how it is stored, processed, and shared across systems and third parties. These are operational and organizational practices rather than legal instruments in themselves; while frequently undertaken to support obligations under regulations such as the GDPR (EU) and CCPA (California), the specific documentation requirements, scope, and triggering conditions differ by jurisdiction, data category, and organizational role (for example controller versus processor). Readers should treat the inventory and map as living artifacts requiring periodic review, and verify particular recordkeeping obligations against the applicable current legal text.
Why it matters
An organization cannot protect, govern, or account for data it has not catalogued. Data inventory and mapping give compliance, privacy, and security teams a foundational picture of what data exists, where it resides, how it is used, and who can access it. Without that picture, obligations that depend on knowing one's data holdings—responding to individual rights requests, assessing breach scope, or documenting processing activities—become difficult to satisfy reliably. Many privacy and security programs treat the inventory and map as prerequisites rather than optional refinements.
Under regimes such as the GDPR (EU) and the CCPA (California), organizations may need to demonstrate that they understand and can account for their data flows, though the specific recordkeeping obligations, scope, and triggering conditions differ by jurisdiction, data category, and whether an organization acts as a controller or a processor. A data inventory and map do not by themselves satisfy any particular legal requirement; they are operational practices that support compliance rather than legal instruments that constitute it. Their value lies in enabling an organization to locate relevant data quickly and to substantiate claims about how that data is handled.
Because data landscapes change as systems, vendors, and processing purposes evolve, an inventory and map that are accurate at one point can drift out of date. Treating these artifacts as living records subject to periodic review is generally regarded as important; a stale inventory can create a false sense of coverage and undermine the very programs it is meant to support. Readers should verify their specific documentation obligations against the applicable current legal text.
Who it's relevant to
Inside Data Inventory and Mapping
Common questions
Answers to the questions practitioners most commonly ask about Data Inventory and Mapping.

