Data Flow Mapping
What is Data Flow Mapping?
The visual documentation of how personal data moves through an organization's systems, processes, and third parties to identify privacy risks and compliance gaps.
Terms that appear alongside data flow mapping
Each of these is named in at least one of the same controls as data flow mapping. The number is how many controls name both.
- data protection 2 shared controls
- asset management 2 shared controls
- cybersecurity 2 shared controls
- privacy framework 2 shared controls
Frameworks that govern data flow mapping
What the standards actually require on data flow mapping
Requirements naming data flow mapping across 6 standards, quoted from the control text.
Asset management and data flow mapping. Implements CyFun ID.AM-3 / ID.AM-4: organisational communication and data flows are mapped and external information systems are catalogued.
BE-CF-33 · Asset management and data flow mapping →Map the data flows between DER assets, aggregators, distribution operators, and grid operators, including command and telemetry channels.
DER-ID-02 · Data Flow Mapping for DER →Article 12 of the Kazakhstan PDPL establishes the data localization requirement for biometric personal data of Kazakhstan citizens and residents - a key sovereignty provision strengthened by the 2022 amendment.
KZ-PDPL-Biometric-Data-Localization-Article12-Server-Kazakhstan-On-Soil-Data-Storage-Citizens-Residents · Kazakhstan PDPL Biometric Data Localization + Article 12 + Mandatory Server Storage in Kazakhstan + 2022 Amendment + Citizens + Residents + Foreign Cloud Provider Restrictions + Data Sovereignty + State Service for Information Security Oversight →Apply NIST Privacy Framework v1.0 (January 2020) Identify-P function categories: Business Environment (ID.BE-P) covering organizational mission + roles + responsibilities + stakeholders;
NISTPF-1 · Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment →Apply Section 6 data classification and handling in cloud per FIPS 199 categorisation + agency data sensitivity + GDPR + CCPA + 24 state privacy laws + HIPAA + PCI DSS + SOX.
NISTSP144-3 · Data Classification, Handling, and Sovereignty →Protect patron data + employee data + financial transaction data + responsible gaming data per NGC 5.260(i). Maintain data inventory + classification scheme (confidential + restricted + internal + public) + data flow mapping.
NGCB-7 · Patron and Employee Data Protection + Data Inventory + Vendor Management →Questions people ask about data flow mapping
What is Data Flow Mapping?
Why is Data Flow Mapping important for compliance?
Which compliance frameworks address Data Flow Mapping?
Where can I learn more about Data Flow Mapping?
See how Data Flow Mapping applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.