About this program
You cannot protect what you cannot find. Quick check of PII discovery, mapping and minimisation.
Risks addressed
- Critical Unknown PII stores exposed in a breach
- High PII kept past the retention period (GDPR breach)
- High Production data copied to test / dev environments
Controls (6)
-
Discovery tool scans structured + unstructured data
HighData discovery tools are deployed to automatically scan both structured data repositories (databases, data warehouses) and unstructured data stores (file shares, cloud storage buckets, email archives, collaboration platforms) to identify, classify, and inventory sensitive information such as PII, PHI, PCI,…
How to test + evidence
Testing procedure: Tool (Varonis / Microsoft Purview / equivalent) scans file shares, databases, SaaS.
Evidence to collect: Tool inventory + last scan.
-
Data inventory / RoPA maintained
HighThis control requires organizations to maintain a comprehensive, current inventory of all personal data processing activities, typically documented in a Record of Processing Activities (RoPA) as mandated by GDPR Article 30 and similar privacy regulations. The inventory identifies what data…
How to test + evidence
Testing procedure: Article-30 record of processing activities up to date.
Evidence to collect: RoPA document.
-
Retention policy + scheduled deletion
HighThis control ensures that data is retained only for the period necessary to meet business, legal, and regulatory requirements, and is automatically deleted thereafter. Organizations define retention periods by data classification, implement scheduled deletion processes (e.g., cron jobs, cloud lifecycle…
How to test + evidence
Testing procedure: Per data-type retention; automated deletion / archive at end of life.
Evidence to collect: Retention policy + delete jobs.
-
No production PII in non-prod
CriticalThis control prohibits the use of production personally identifiable information (PII) in non-production environments including development, testing, staging, and sandbox systems. Organizations must implement technical and procedural safeguards to ensure that test data is either synthetically generated, anonymized, or de-identified…
How to test + evidence
Testing procedure: Test / dev environments use anonymised / synthetic data.
Evidence to collect: Pipeline + masking config.
-
DSAR process tested
MediumThis control validates that an organization's Data Subject Access Request (DSAR) process is periodically tested to confirm it can identify, retrieve, and deliver personal data to requestors within regulatory timeframes. Testing typically involves simulating requests across systems, verifying search coverage,…
How to test + evidence
Testing procedure: Subject access request workflow tested at least once per year.
Evidence to collect: DSAR test report.
-
PII access reviewed quarterly
MediumThis control mandates a formal quarterly review of all user access rights to systems, applications, and databases containing personally identifiable information (PII). The review verifies that only authorized individuals retain access based on current job responsibilities and business justification. Quarterly…
How to test + evidence
Testing procedure: Access to PII stores recertified by owners every quarter.
Evidence to collect: Recert report.