English

Open Circle AG – Zurich
Freilagerstrasse 32
8047 Zürich

Open Circle AG – Bern
Lagerhausweg 30
3018 Bern

Back
1/11

Define the objective and framework

  • Why? Clarify the purpose of creating the data inventory. (e.g. GDPR compliance, transparency, increased efficiency, data quality)
  • Scope: Determine whether only personal data should be collected or all business-relevant data.
  • Responsibilities: Appoint a responsible person or team
2/11

Identify data sources

Identify where your company obtains data from.

  • For example, job applications, employees, newsletter subscriptions, customers, contact forms on the website, etc.
  • Systems and applications (e.g. ERP, CRM, HR software)
  • Databases (e.g. SQL, NoSQL)
  • Cloud services and local storage
  • Files and documents (Excel, Word, PDFs)
  • Manual data sets (e.g. paper archives)
3/11

Record type of data/designation including precise description

Describe exactly what data you store. For example:

  • Employee data (email address, surname, first name, date of birth, portrait photo)
  • Prospective customer data (email, surname, first name, telephone number, company, address)
  • Bank details (account number, IBAN, bank, etc.)
  • Log files
  • Passwords
  • Credit card information
  • etc.
4/11

Document processing purposes

Document the purpose of data collection/processing

  • e.g. contract processing, recruitment, customer acquisition, personnel administration, payroll, etc.
  • What is the legal basis (for personal data, e.g. GDPR Art. 6)?
5/11

Responsible person & department

  • Who is responsible for the data? Function, specific person such as marketing manager, HR specialist, etc.
  • Which department is responsible for the data? Marketing, human resources, finance, etc.
6/11

Enter data category

Categorise your data according to sensitivity. Is it personal data, etc.? How important is the data for the company?

  • Assess your data according to business criticality (1-low, 2-normal, 3-high, 4-critical).
  • Assess your data according to the CIA/D method (confidentiality, integrity, availability, data protection relevance).
7/11

Document access rights

Record access rights. Who has access, what are their roles and permissions? For example, marketing (MK), sales (SA), etc.

8/11

Record storage location and retention periods

Carefully describe where the data is stored: tool/system and its storage location/data centre.

  • Tool/system/format (password manager, Hubspot CRM, Trello board, Excel spreadsheet, images)
  • Storage location (file server, Nextcloud, Cloud XY, Hostpoint, including exact location/address of data centre) If you do not know a location, ask explicitly or consult contracts.
  • Retention periods and deletion (how long is data stored? How and when is it deleted? Manually, automatically, etc.) Observe the regulatory deadlines.
9/11

Record data flows & third parties

Record exactly where the data flows to. Is it passed on to third parties?

  • Where does the data go (output, interfaces)?
  • Do external third parties (service providers, partners) have access?

Tip: A data flow diagram helps to identify dependencies and risks.

10/11

Document risks and protective measures

  • Security measures (encryption, access controls, backups)
  • Vulnerabilities and risks
11/11

Maintain and update inventory

  • Create a central document or tool (e.g. Excel, data management software, GDPR tool)
  • Ensure regular updates (e.g. once a year or when system changes are made)
  • Integrate the inventory into governance and compliance processes

Create data inventory now

Would you like to create your own data inventory? Download our free template now.

Get advice