03 / In your browser / VERSION 0.4.0

Data Inventory Mapper

Turn disconnected system knowledge into a reviewable processing inventory.

LOCAL INSTRUMENT / SYNTHETIC EXAMPLE INCLUDED

Method

Normalises twelve canonical fields into four completeness lanes, a paged table and an editable source-to-system-to-recipient relationship projection.

Use it safely

Begin with the synthetic example in the toolbench, then minimise any real-world input. Inspect each finding, its source/status note and the facts behind it before exporting a result.

What it cannot determine

It cannot discover systems or data, validate evidence links, determine legal roles or purposes, test controls or prove that an inventory is complete.

Processing boundary. This preview processes current input in browser memory. No input is submitted or stored by dpdp.store. Results are evidence-building aids, not legal approval, certification or an official schema.

9 minute working guide / SYNTHETIC WALKTHROUGH

From input to a reviewable handoff.

GUIDE 0.5
Reviewed
2026-08-26
Legal status
editorial analysis
Source/method records
dpdp-store-method-0.5
Changelog
0.5.0 — added four completeness lanes, paged row operations, controlled states, possible-duplicate cues, relationship editing and a data-minimised review export.

What this produces: A bounded, editable processing inventory plus a data-minimised review record in JSON, spreadsheet-safe CSV or a script-free HTML report.

FICTIONAL PRACTICE SCENARIO

A fictional internal team maps an enquiry form, support inbox and reporting store, including their purposes, people groups, processors, owners, regions, retention triggers and evidence links.

Before you begin

  • Begin with one business process and a named system owner rather than attempting an organisation-wide map in one sitting.
  • Use category labels instead of personal records; evidence links should point to controlled locations, not contain secrets.
  • Agree a vocabulary for systems, purposes, people groups and data categories before merging contributions.

Walk the evidence sequence

  1. Load and verify the CSV shape

    Open the synthetic example, compare its headers with your minimised CSV and import it locally. Resolve quoting or row-limit errors before editing.

    Evidence to inspect
    The parser reports a bounded row set, discloses unrecognised columns and opens all canonical records in 25-row editor pages.
    Human review
    A successfully parsed file may still omit shadow systems, manual exports, backups or informal recipients.
  2. Describe purpose and movement

    For each system, connect data categories and people groups to a specific purpose, source and recipient or processor.

    Evidence to inspect
    The table and relationship editor present the supplied source → system → recipient claim without calling it a discovered flow.
    Human review
    Avoid vague purposes such as “business use”; ask what happens, for whom and why.
  3. Add accountability and lifecycle evidence

    Record the owner, region, retention trigger, deletion mechanism, security class and evidence links. Treat unknown as a visible state rather than guessing.

    Evidence to inspect
    Editing either view refreshes four lane counts, row states and current exports; possible duplicate and over-broad vocabulary cues remain visible.
    Human review
    Check backup, archive, derived dataset and processor copies instead of assuming the primary-system deletion covers them.
  4. Choose the right handoff format

    Use records JSON for the full canonical data, review JSON for a value-free state record, formula-safe CSV for controlled spreadsheet work or the inert HTML report for a readable snapshot.

    Evidence to inspect
    The review JSON omits cell values; the HTML report has no scripts or external resources; every download needs an explicit local action.
    Human review
    Store the export under your own access, retention and version controls; clearing the tab cannot remove downloaded copies.

Handoff check

  • Has every row been confirmed by someone who understands the system?
  • Are processors, recipients, regions and evidence links current?
  • Do retention triggers describe observable events rather than vague durations?
STOP / REVIEW BOUNDARY

The mapper organises supplied facts. It does not discover systems, scan networks, verify evidence links or prove that the inventory is complete.

Security and parsing

  • Inputs have byte, row or component limits appropriate to the parser.
  • Imported content is treated as text or data and is never executed.
  • Spreadsheet exports neutralise formula-leading cells.
  • Use the per-tool reset or “Clear current toolbench state” to remove current in-tab input and results. Downloaded files remain under your control.

Version record

0.4.0 · 26 August 2026: deterministic public static implementation, synthetic fixture and bounded local parser. Guide record 0.5 · 26 August 2026.