Data Flow Mapping - Top-Down and Bottom-Up
After inventory and classification, data flows are mapped and documented (what, where, and why data is processed). The top-down approach used for regulatory purposes often starts with the GDPR-required RoPA; the bottom-up approach builds from data assets through to data lineage.
How this supports CIPP/US study
Use this lesson to connect a privacy programme decision with the relevant regulator, duty or enforcement route. Continue with the CIPP/US study guide.
Once inventoried and classified, data flows are examined and documented. Mapping answers: what data is processed, where, and why. There are two common approaches.
| Approach | Description |
|---|---|
| Top-down | Typically used for regulatory purposes; often starts with the GDPR-required record of processing activities (RoPA) documenting purpose, recipients, retention, and safeguards |
| Bottom-up | Insightful for privacy pros; steps: understand data assets, inventory and classification, delineate data processes (can use RoPA), then document data lineage |
RoPA can be hard to validate and keep current, so many organizations automate it with technology. Data lineage adds metadata identifying the original source of data, the most critical data, and how data sets are built and aggregated.
Key terms - quick answers
What is “Data flow mapping”?
What is “Record of processing activities (RoPA)”?
What is “Data lineage”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.