Map more than the primary database

List the information collected, whose information it is, the purpose of processing and each recipient. Include backups, support access, logs, analytics and AI providers. A database hosted in one place does not establish that every related processing activity stays there. Give this map to the person responsible for legal and privacy review.

Map an overseas support session

An example service stores its main database in Hong Kong but allows an overseas support team to inspect error reports. This engineering worksheet exposes the information flow for privacy review; it does not decide whether a transfer is lawful.

Map an overseas support session
Flow to documentFacts the reviewer needs
Error report sent to supportFields included, recipient, processing location and purpose
Backup replicated by a providerActual storage regions, subcontractors and retention settings
Remote database accessRoles allowed, access period, approval owner and audit trail

Assess the actual transfer arrangement

Hong Kong, Mainland and European requirements should not be treated as interchangeable. Applicable duties depend on the facts and jurisdictions involved. The PCPD publishes recommended model contractual clauses for cross-border transfers; these are a reference for review rather than proof that any particular transfer is compliant.

Translate the decision into system behaviour

Once advisers establish the requirements, identify the access restrictions, location choices, retention rules and evidence the system needs. Check vendors and onward processing as well as the first transfer. Keep the map current when adding a new integration or support arrangement so the original review does not become obsolete unnoticed.

Before you proceed

  • Include logs, backups and remote support in the data map.
  • Have the applicable requirements assessed for the actual arrangement.
  • Record provider responsibilities and review changes.

Sources & further reading

Put this into practice