Map more than the primary database
List the information collected, whose information it is, the purpose of processing and each recipient. Include backups, support access, logs, analytics and AI providers. A database hosted in one place does not establish that every related processing activity stays there. Give this map to the person responsible for legal and privacy review.
Map an overseas support session
An example service stores its main database in Hong Kong but allows an overseas support team to inspect error reports. This engineering worksheet exposes the information flow for privacy review; it does not decide whether a transfer is lawful.
| Flow to document | Facts the reviewer needs |
|---|---|
| Error report sent to support | Fields included, recipient, processing location and purpose |
| Backup replicated by a provider | Actual storage regions, subcontractors and retention settings |
| Remote database access | Roles allowed, access period, approval owner and audit trail |
Assess the actual transfer arrangement
Hong Kong, Mainland and European requirements should not be treated as interchangeable. Applicable duties depend on the facts and jurisdictions involved. The PCPD publishes recommended model contractual clauses for cross-border transfers; these are a reference for review rather than proof that any particular transfer is compliant.
Translate the decision into system behaviour
Once advisers establish the requirements, identify the access restrictions, location choices, retention rules and evidence the system needs. Check vendors and onward processing as well as the first transfer. Keep the map current when adding a new integration or support arrangement so the original review does not become obsolete unnoticed.
Before you proceed
- Include logs, backups and remote support in the data map.
- Have the applicable requirements assessed for the actual arrangement.
- Record provider responsibilities and review changes.



