Skip to main content

Pro audit program · v1.0

PII Data Discovery

You cannot protect what you cannot find. Quick check of PII discovery, mapping and minimisation.

  • General target area
  • GDPR / ISO 27701 framework
  • 6 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

You cannot protect what you cannot find. Quick check of PII discovery, mapping and minimisation.

Risks addressed

  • Critical Unknown PII stores exposed in a breach
  • High PII kept past the retention period (GDPR breach)
  • High Production data copied to test / dev environments

Controls (6)

  1. Discovery tool scans structured + unstructured data

    High

    Data discovery tools are deployed to automatically scan both structured data repositories (databases, data warehouses) and unstructured data stores (file shares, cloud storage buckets, email archives, collaboration platforms) to identify, classify, and inventory sensitive information such as PII, PHI, PCI,…

    How to test + evidence

    Testing procedure: Tool (Varonis / Microsoft Purview / equivalent) scans file shares, databases, SaaS.

    Evidence to collect: Tool inventory + last scan.

  2. Data inventory / RoPA maintained

    High

    This control requires organizations to maintain a comprehensive, current inventory of all personal data processing activities, typically documented in a Record of Processing Activities (RoPA) as mandated by GDPR Article 30 and similar privacy regulations. The inventory identifies what data…

    How to test + evidence

    Testing procedure: Article-30 record of processing activities up to date.

    Evidence to collect: RoPA document.

  3. Retention policy + scheduled deletion

    High

    This control ensures that data is retained only for the period necessary to meet business, legal, and regulatory requirements, and is automatically deleted thereafter. Organizations define retention periods by data classification, implement scheduled deletion processes (e.g., cron jobs, cloud lifecycle…

    How to test + evidence

    Testing procedure: Per data-type retention; automated deletion / archive at end of life.

    Evidence to collect: Retention policy + delete jobs.

  4. No production PII in non-prod

    Critical

    This control prohibits the use of production personally identifiable information (PII) in non-production environments including development, testing, staging, and sandbox systems. Organizations must implement technical and procedural safeguards to ensure that test data is either synthetically generated, anonymized, or de-identified…

    How to test + evidence

    Testing procedure: Test / dev environments use anonymised / synthetic data.

    Evidence to collect: Pipeline + masking config.

  5. DSAR process tested

    Medium

    This control validates that an organization's Data Subject Access Request (DSAR) process is periodically tested to confirm it can identify, retrieve, and deliver personal data to requestors within regulatory timeframes. Testing typically involves simulating requests across systems, verifying search coverage,…

    How to test + evidence

    Testing procedure: Subject access request workflow tested at least once per year.

    Evidence to collect: DSAR test report.

  6. PII access reviewed quarterly

    Medium

    This control mandates a formal quarterly review of all user access rights to systems, applications, and databases containing personally identifiable information (PII). The review verifies that only authorized individuals retain access based on current job responsibilities and business justification. Quarterly…

    How to test + evidence

    Testing procedure: Access to PII stores recertified by owners every quarter.

    Evidence to collect: Recert report.