← Back to Data Processor Workflows: Third-Party Risks
Creating a Comprehensive Data Inventory
You cannot protect what you cannot see. A data inventory (also called a record of processing activities) is the master map of every type of personal data your organisation holds, where it lives, who touches it, and why. It is the first deliverable any serious compliance programme produces — and the first thing a regulator will ask to see.
What the inventory must capture
For each processing activity, record at minimum:
- Data categories — e.g. customer contact details, TRNs, health data, CCTV footage
- Data subjects — customers, employees, job applicants, website visitors
- Purpose — why you hold it, in one plain sentence
- Lawful basis — consent, contract, legal obligation, etc.
- Storage location — server, SaaS tool, filing cabinet, staff WhatsApp (yes, that counts)
- Access — which roles and which third parties can see it
- Retention period — how long you keep it and what triggers deletion
- Cross-border transfers — does it leave Jamaica (most cloud tools mean yes)
How to actually build it
Step 1: Interview, don’t assume
Sit with each department for 30 minutes. Ask: “Walk me through what happens when a new customer signs up / an employee is hired / a complaint comes in.” Shadow the process. The unofficial spreadsheets and WhatsApp groups you discover this way are exactly the risks the inventory exists to expose.
Step 2: Follow the data, not the department
Data flows across teams. A job application touches HR, the hiring manager’s inbox, maybe a background-check vendor. Map the journey end to end — collection, use, storage, sharing, destruction.
Step 3: Assign an owner to every row
Every processing activity needs a named person responsible for keeping that row accurate. An inventory with no owners is out of date within three months.
A Kingston BPO builds its first inventory and discovers team leads have been exporting customer call logs to personal Google Sheets to build performance dashboards. Nobody was malicious — the official reporting tool was slow. But overseas client data was sitting in unmanaged personal accounts. The inventory exercise surfaced it, IT built a proper dashboard, and the exports stopped. This is the pattern: inventories find shadow systems before regulators or attackers do.
Quick check: Your company uses Gmail, QuickBooks Online, and a US-hosted CRM. How many cross-border transfers is that?
At least three. Each cloud service hosted outside Jamaica is a transfer of personal data abroad and must appear in the inventory with the safeguard relied upon (e.g. contract clauses with the provider). This is why the transfer column is rarely empty in practice.
Quick check: Should paper records be in a data inventory?
Absolutely. The JDPA covers structured paper filing systems. Personnel files in a cabinet, visitor log books, and signed consent forms all belong in the inventory — with their physical location and who holds the key.
- A data inventory maps what personal data you hold, where, why, who accesses it, and when it is destroyed.
- Build it by interviewing departments and following data flows end to end — shadow systems are the point.
- Every row needs a named owner and a review date, or the inventory rots.
- Cloud tools hosted abroad are cross-border transfers and must be recorded with their safeguards.