GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DAT-006 Data Inventory and Records of Processing

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A current inventory of personal and sensitive data assets is maintained, documenting data categories, processing purposes, data flows, retention periods, legal basis for processing, and the systems and third parties involved. This record is reviewed and updated at least annually.

Rationale

A data inventory is the foundational accountability artefact for privacy compliance. It enables proportionate protection, supports DPIA scoping, facilitates data subject rights fulfilment, and is required by GDPR Art.30.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
Data Act Cloud Provider (EU)stablerequiredrole duty

Art. 25(2)(e) and (f) need the inventory to reach beyond personal and sensitive data. The exhaustive specification of portable categories is drawn from it and so is the separation of provider-internal categories that may be exempted on trade secret grounds, which Art. 25(2)(f) allows only where the exemption does not impede or delay the switch.

DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (16)

DSP-03Data Inventoryfull
DSP-05Data Flow Documentationpartial
DSP-06Data Ownership and Stewardshippartial
DSP-20Data Provenance and Transparencyinformative
DSP-03Data Inventoryfull
DSP-05Data Flow Documentationpartial
DSP-06Data Ownership and Stewardshippartial
EU-DA-Art.25.2.eExhaustive Specification of Portable Data and Digital Assetsinformative
GDPR-Art.30.1Controller Records of Processing Activities (RoPA)partial
GDPR-Art.30.2Processor Records of Processing Activitiespartial
GDPR-Art.5.2Accountability Principlepartial
HIPAA-164.308.a.1.ii.ARisk Analysisinformative
NIS2-CIR-12.4Asset Inventoryinformative
CM-13Data Action Mappingfull
PM-18Privacy Program Planinformative
C1.1Confidential Information Identification and Maintenanceinformative

Evidence (2)

reportdocumentmanual

Records of Processing Activities (RoPA) or data inventory documenting all personal data processing activities with required GDPR Art.30 fields.

Example: RoPA register (OneTrust / Confluence / spreadsheet), listing each processing activity with: controller identity, processing purpose, data categories, data subject categories, recipients, third countries, retention periods, legal basis, and technical/organisational measures, reviewed within 12 months

Test: Request the current RoPA or data inventory. Verify: (1) all active processing activities are represented, (2) each entry includes: purpose, data categories, legal basis, retention period, and any third-party recipients, (3) cross-border transfers are identified and transfer mechanisms documented, (4) register has been reviewed and updated within the last 12 months, (5) DPO or data owner approval is recorded.

recorddocumentmanual

Data flow diagram or automated data mapping output showing how personal data moves between systems and to third parties.

Example: Automated data flow map export from OneTrust Data Mapping, Securiti.ai, or equivalent, showing data flows from collection points to processing systems to third-party processors, with data categories annotated

Test: Request the data flow diagram or mapping tool export. Verify: (1) all major data collection touchpoints are shown (web app, mobile, API, support systems), (2) flows to all identified third-party processors are represented, (3) any cross-border flows are marked, (4) diagram is dated within 12 months.

Questions (2)

boolean

Does your organisation maintain a current Records of Processing Activities (RoPA) or equivalent data inventory documenting all personal data processing with the fields required by GDPR Article 30?

The RoPA must include: processing purposes, data categories, data subject categories, legal basis, retention periods, third-party recipients, cross-border transfers, and applicable safeguards. It should be reviewed and updated at least annually.

select

How is the data inventory or RoPA maintained?

Privacy management platform that discovers data flows and flags entries that have gone out of dateRegister held in a documentation or collaboration system with a named owner and a scheduled reviewSpreadsheet maintained by the privacy or legal teamNo structured record: data flows are described informally

Options run from the strongest record to the weakest. A privacy management platform discovers flows and raises the entries nobody has touched; OneTrust, Securiti and TrustArc are examples of the category. A register in a documentation or collaboration system such as Confluence, Notion or SharePoint holds up where the number of processing activities is small and one person owns the review. A spreadsheet is acceptable at that size and fails the same way a register does, by going stale between annual reviews with nobody watching.