← Back to Data Processor Workflows: Third-Party Risks

Creating a Comprehensive Data Inventory

You cannot protect what you cannot see. A data inventory (also called a record of processing activities) is the master map of every type of personal data your organisation holds, where it lives, who touches it, and why. It is the first deliverable any serious compliance programme produces — and the first thing a regulator will ask to see.

What the inventory must capture

For each processing activity, record at minimum:

How to actually build it

Step 1: Interview, don’t assume

Sit with each department for 30 minutes. Ask: “Walk me through what happens when a new customer signs up / an employee is hired / a complaint comes in.” Shadow the process. The unofficial spreadsheets and WhatsApp groups you discover this way are exactly the risks the inventory exists to expose.

Step 2: Follow the data, not the department

Data flows across teams. A job application touches HR, the hiring manager’s inbox, maybe a background-check vendor. Map the journey end to end — collection, use, storage, sharing, destruction.

Step 3: Assign an owner to every row

Every processing activity needs a named person responsible for keeping that row accurate. An inventory with no owners is out of date within three months.

🌴 Jamaica Scenario: The BPO discovery

A Kingston BPO builds its first inventory and discovers team leads have been exporting customer call logs to personal Google Sheets to build performance dashboards. Nobody was malicious — the official reporting tool was slow. But overseas client data was sitting in unmanaged personal accounts. The inventory exercise surfaced it, IT built a proper dashboard, and the exports stopped. This is the pattern: inventories find shadow systems before regulators or attackers do.

Quick check: Your company uses Gmail, QuickBooks Online, and a US-hosted CRM. How many cross-border transfers is that?

At least three. Each cloud service hosted outside Jamaica is a transfer of personal data abroad and must appear in the inventory with the safeguard relied upon (e.g. contract clauses with the provider). This is why the transfer column is rarely empty in practice.

Quick check: Should paper records be in a data inventory?

Absolutely. The JDPA covers structured paper filing systems. Personnel files in a cabinet, visitor log books, and signed consent forms all belong in the inventory — with their physical location and who holds the key.

Key Takeaways
  • A data inventory maps what personal data you hold, where, why, who accesses it, and when it is destroyed.
  • Build it by interviewing departments and following data flows end to end — shadow systems are the point.
  • Every row needs a named owner and a review date, or the inventory rots.
  • Cloud tools hosted abroad are cross-border transfers and must be recorded with their safeguards.