Method
Normalises twelve canonical fields into four completeness lanes, a paged table and an editable source-to-system-to-recipient relationship projection.
Use it safely
Begin with the synthetic example in the toolbench, then minimise any real-world input. Inspect each finding, its source/status note and the facts behind it before exporting a result.
What it cannot determine
It cannot discover systems or data, validate evidence links, determine legal roles or purposes, test controls or prove that an inventory is complete.
9 minute working guide / SYNTHETIC WALKTHROUGH
From input to a reviewable handoff.
- Reviewed
- 2026-08-26
- Legal status
- editorial analysis
- Source/method records
- dpdp-store-method-0.5
- Changelog
- 0.5.0 — added four completeness lanes, paged row operations, controlled states, possible-duplicate cues, relationship editing and a data-minimised review export.
What this produces: A bounded, editable processing inventory plus a data-minimised review record in JSON, spreadsheet-safe CSV or a script-free HTML report.
A fictional internal team maps an enquiry form, support inbox and reporting store, including their purposes, people groups, processors, owners, regions, retention triggers and evidence links.
Before you begin
- Begin with one business process and a named system owner rather than attempting an organisation-wide map in one sitting.
- Use category labels instead of personal records; evidence links should point to controlled locations, not contain secrets.
- Agree a vocabulary for systems, purposes, people groups and data categories before merging contributions.
Walk the evidence sequence
Load and verify the CSV shape
Open the synthetic example, compare its headers with your minimised CSV and import it locally. Resolve quoting or row-limit errors before editing.
- Evidence to inspect
- The parser reports a bounded row set, discloses unrecognised columns and opens all canonical records in 25-row editor pages.
- Human review
- A successfully parsed file may still omit shadow systems, manual exports, backups or informal recipients.
Describe purpose and movement
For each system, connect data categories and people groups to a specific purpose, source and recipient or processor.
- Evidence to inspect
- The table and relationship editor present the supplied source → system → recipient claim without calling it a discovered flow.
- Human review
- Avoid vague purposes such as “business use”; ask what happens, for whom and why.
Add accountability and lifecycle evidence
Record the owner, region, retention trigger, deletion mechanism, security class and evidence links. Treat unknown as a visible state rather than guessing.
- Evidence to inspect
- Editing either view refreshes four lane counts, row states and current exports; possible duplicate and over-broad vocabulary cues remain visible.
- Human review
- Check backup, archive, derived dataset and processor copies instead of assuming the primary-system deletion covers them.
Choose the right handoff format
Use records JSON for the full canonical data, review JSON for a value-free state record, formula-safe CSV for controlled spreadsheet work or the inert HTML report for a readable snapshot.
- Evidence to inspect
- The review JSON omits cell values; the HTML report has no scripts or external resources; every download needs an explicit local action.
- Human review
- Store the export under your own access, retention and version controls; clearing the tab cannot remove downloaded copies.
Handoff check
- Has every row been confirmed by someone who understands the system?
- Are processors, recipients, regions and evidence links current?
- Do retention triggers describe observable events rather than vague durations?
The mapper organises supplied facts. It does not discover systems, scan networks, verify evidence links or prove that the inventory is complete.
Security and parsing
- Inputs have byte, row or component limits appropriate to the parser.
- Imported content is treated as text or data and is never executed.
- Spreadsheet exports neutralise formula-leading cells.
- Use the per-tool reset or “Clear current toolbench state” to remove current in-tab input and results. Downloaded files remain under your control.
Version record
0.4.0 · 26 August 2026: deterministic public static implementation, synthetic fixture and bounded local parser. Guide record 0.5 · 26 August 2026.