Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations prepare for GDPR when they…
Governance, Ownership & Risk

How should organisations prepare for GDPR when they do not yet know where all personal EU data sits?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

Start with data discovery and documentation before expanding controls. Organisations need a current inventory of where personal EU data is stored, processed, and shared, then map the internal processes that touch it. Without that baseline, encryption, awareness training, and advanced security tools can reduce exposure but still leave major compliance gaps because teams cannot prove scope or control.

Why the first job is proving scope, not adding controls

When organisations do not yet know where all personal EU data sits, the immediate task is discovery and documentation. GDPR readiness starts with a current inventory of where data is stored, processed, and shared, plus the business processes and systems that touch it. That inventory is what turns privacy from assumption into something teams can govern, defend, and evidence.

At this stage, the point is not perfection. It is to identify the systems, exports, backups, shared drives, tickets, logs, and third-party flows that may contain personal data so the organisation can define scope and ownership. Without that baseline, security controls may exist, but they cannot be targeted, measured, or shown to cover the full data lifecycle.

A useful way to think about the problem is that GDPR obligations become operational only after data locations and purposes are mapped. That means records of processing, retention, sharing, and lawful basis depend on having a usable view of the data estate. For readers building the baseline, the EU General Data Protection Regulation (GDPR) is the starting point for the underlying obligations, while the NIST Privacy Framework is useful for structuring discovery, governance, and privacy risk management.

What “good enough” discovery looks like in practice

Good-enough discovery is not a one-off spreadsheet. It is an evidence-backed inventory that identifies systems of record, shadow data stores, data flows, and the teams responsible for each. Organisations should expect to reconcile technical sources with business process knowledge, because personal data often appears in places that standard asset inventories miss, such as collaboration tools, analytics extracts, support systems, and externally shared documents.

Documentation should also capture what type of EU personal data is present, why it exists, how long it is retained, and who receives it. That matters because different data categories and use cases create different obligations, especially where special category data, profiling, or cross-border sharing is involved. In parallel, this is where Identity Security Regulatory Map can help teams connect governance questions to concrete control expectations, and Identity Data Privacy and Consent Guide is relevant where user data handling, retention, and consent-led processing need tighter definition.

The practical test is whether a privacy or security team can answer, with evidence, where the data lives today, who can reach it, and which processes move it. If the answer is incomplete, the organisation should treat that as a scope gap rather than a tooling gap. Controls such as encryption, access restrictions, and monitoring still matter, but they work best after the inventory reveals where to apply them.

Which controls should follow once the baseline exists

After discovery, organisations can phase in controls in a defensible order. Start with data classification, access limitation, retention rules, and logging for the most exposed stores and transfer paths. Then expand to encryption, DLP, secure deletion, supplier oversight, and privacy-by-design changes in the systems that process the highest-risk data.

The key is sequencing. Applying advanced security tooling before the inventory is complete can create a false sense of compliance, because teams may protect known systems while missing unknown copies or unmanaged exports. A broader control programme is still necessary, but it should be anchored to the discovered data map so the organisation can show proportionate coverage and respond to requests, incidents, and audits with confidence.

For organisations that want an external control lens, CIS Controls v8 aligns well with the need for asset inventory, data protection, access control, and logging, while GDPR remains the legal frame that determines whether the control set is actually sufficient for the data in scope.

Risk and Threat Considerations

The main risk is not simply that personal data exists in many places, but that the organisation cannot demonstrate where it is, who can access it, or whether it is still needed. That creates compliance exposure, weakens incident response, and makes privacy obligations hard to evidence when regulators, customers, or internal auditors ask for proof.

Failure mechanism: Unmapped data stores, unmanaged copies, and undocumented sharing paths leave gaps in retention, access control, and breach response. When teams do not know the true scope, they cannot reliably delete, restrict, or investigate the data that matters most.

Impact: The organisation may over-collect, over-retain, or under-protect personal EU data, and it may be unable to prove that controls cover all relevant processing. That increases the chance of regulatory findings, delayed incident containment, and repeated remediation work.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt. 5 — Principles relating to processing of personal dataDiscovery and mapping support lawful, transparent, limited processing.
Art. 25 — Data protection by design and by defaultBaseline inventory is needed before privacy-by-design controls can be applied properly.
Art. 30 — Records of processing activitiesThe question is fundamentally about documenting where personal data sits and moves.
Recommendation — Map data flows and retention to show lawful, purpose-limited processing. Use the inventory to embed privacy-by-design into systems and processes. Maintain records of processing that reflect current systems, purposes, and sharing.
NIST CSF 2.0ID.AM-01 — Physical devices and systems are inventoriedAn inventory is central to finding where personal data resides and is processed.
ID.AM-02 — Software platforms and applications are inventoriedApplications often host or move personal data that must be documented.
PR.DS-01 — Data-at-rest is protectedOnce scope is known, data-at-rest protections can be applied to the right stores.
Recommendation — Inventory the systems that store or process personal EU data. Catalogue applications that process or share personal EU data. Protect discovered personal-data stores with appropriate at-rest controls.
NIST SP 800-53 Rev 5CM-8 — System Component InventoryA current inventory is needed to locate systems holding personal EU data.
RA-3 — Risk AssessmentUnknown data locations create risk that must be assessed before control expansion.
AR-2 — Privacy Impact and Risk AssessmentPrivacy risk assessment depends on knowing where personal data is processed.
Recommendation — Maintain an accurate inventory of systems that touch personal EU data. Assess exposure created by unknown or undocumented personal-data locations. Use privacy risk assessments to drive remediation after discovery.

Practitioner Guidance

What to prioritise: Build a minimum viable data inventory first, focused on the highest-risk business processes, systems of record, shared repositories, and outbound data flows. If you cannot trace a dataset from source to destination, treat that traceability gap as a remediation item.

What to verify: Confirm that each important dataset has an owner, a business purpose, a retention decision, and at least one documented technical location. You should also verify that backups, exports, and third-party transfers are included, because these are common blind spots in GDPR programmes.

Practitioner takeaway: The most effective GDPR preparation sequence is discovery, documentation, then control hardening, because controls without scope are difficult to defend and easy to miss in practice.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org