One inventory the whole privacy programme reads from.
Systems, applications, vendors and data sources — each with a named owner, a lifecycle stage and a business unit. Read by RoPA, DSR, incidents, retention and reports.
For CIOs and DPOs who cannot answer 'which systems hold personal data?' with a single defensible list today.
Without one inventory, every downstream record is guesswork.
RoPA cannot cite systems that are not listed. DSRs cannot be fulfilled against systems no one owns. Incident notifications cannot cite scope you have not mapped.
DPDP §8(4) requires a Data Fiduciary to protect personal data in its possession or under its control — you cannot protect what you have not inventoried.
Three teams keep three lists and none of them agree.
IT owns a CMDB. Procurement owns a vendor list. Security owns a system register. Privacy needs one list, scoped by legal entity, with lifecycle and lawful basis attached.
- Systems, applications, vendors and data sources under one data model.
- Ownership triad on every record: business, technical, accountable.
- Lifecycle stage from onboarding to decommission — with dates.
- Scoped by legal entity, business unit and location.
- Import from Excel and CSV today; connectors for Shopify, SAP, M365, Google Workspace, Zoho and AWS on the roadmap.
From spreadsheet to authoritative register.
Import what you have. Reconcile against connectors as they come online. Attest ownership. Everything else in the platform reads from it.
- 01ImportBring existing lists in via Excel or CSV with validation and preview.
- 02ReconcileMerge duplicates across CMDB, vendor list and privacy inventory.
- 03AttestNamed owner confirms scope, lifecycle stage and criticality.
- 04LinkEach record joins to RoPA, retention schedule, DPA and evidence.
- 05RefreshQuarterly re-attestation with change-log per record.
Every record is owned, dated and evidenced.
No entry sits in the inventory without a named owner and a lifecycle stage. Nothing floats.
- Systems register with ownership and lifecycle
- Applications register mapped to processing activities
- Vendor register with DPA linkage and renewal dates
- Data source register with classification
- Change-log per record
- Auditor-ready inventory export
One answer to 'which systems hold personal data?' — with dates.
RoPA cites real systems. DSRs reach real owners. Incidents cite real scope. Retention runs against real schedules.
- Object types
- Systems · Apps · Vendors · Data
- Import formats
- Excel / CSV
- Attestation cycle
- Quarterly
