Thank you for all the kind notes after last week’s newsletter on the TALK framework. A few of you told me you tried the thirty-second topic prep before a call, and hearing that made my week. Please keep them coming.

Last week we ran another one of our data inventory masterclasses, and I want to share a few of the ideas I keep coming back to. A data inventory is one of my favorite things in all of privacy, even though almost nobody races to build one.

So let me hand you the pieces I hope stick, whether you are building your first inventory, setting up OneTrust for the first time like one of our participants, or avoiding the one that is three years out of date.

If you missed our class, you can join the waitlist to be among the first to know when we announce the next one.

Collect, use, store, share

If you leave this newsletter memorizing four words, memorize these: Collect. Use. Store. Share. And a fifth I will come back to, which is delete. I told the class, if you memorize that and share it with your team, this is going to be huge. I’m like a broken record saying this ALL day long.

So many people think about privacy from the security mindset. Security asks a very fair question, which is tell me where all my data is so I can lock it all up. Companies have been answering that one for years. Here’s what I store. Here are all my systems. Here’s my data in my systems. Lovely. That doesn’t tell you anything about how it’s used.

A data inventory starts somewhere else. It gets to use. That is the fun intersection between privacy and security. You do need to know where the data lives so you can protect it, but that is one piece, not the whole picture. Collect what? Use it for what? Store it where? Share it with whom, and did I tell the person that is what I would do?

Picture the day in the life of one email address. Have you ever signed up for something to get $20 off? I know I have, and yes, the privacy person is happily doing it, because I already know I’m going to buy the thing and they’ll have my email anyway.

Now a company has my name and my email. That email lands in one platform. I place an order, and it often goes to another. One team sends the shipping updates, another asks for a review, then marketing sends more emails to get me to buy more things. One email shows up in multiple systems and several use cases.

And do not forget to ask where the data came from in the first place. Your sales team might be buying data. The source might be a data broker, and they are adding it right into the CRM. If you just looked at Salesforce, you would never know how all that information got in there. Direct from the person, a web form, a subscription, an inference, or it fell from the sky (in case you’re wondering, yes, I really said this).

Where does it come from? Knowing the source of the data is important and starts a long list of other questions. It’s not ONLY what you have; it’s also HOW it got there. And this question changes everything about what companies are allowed to do next.

Here is a trick for when it starts feeling complicated, especially around how to identify processing activities.

I’ve been saying this for years – draw a process out on a whiteboard, and when it starts sprouting a lot of crazy branches, this path going one way and that path going somewhere else, that is usually the sign that what you called one activity is really two.

A processing activity is not one-to-one with a system. It is the story of what you do with the data, and when the story splits, so does the activity.


A data inventory is only as good as the people you talk to

There is good software for completing a data inventory now. Some software will sync to systems and take a decent guess at what marketing or finance is doing, and that is a real help.

Sidebar: do not wait for the perfect tool. I have seen companies do nothing but spin, trying to find the perfect solution, and a year, two years, three years go by and they still have no data inventory. Excel would have been way better than three years of nothing.

It’s why we have a FREE data inventory template on our site – we want companies to be doing something.

But whatever you use, nothing is going to replace talking to Susie Q (this is my new favorite pretend name. I must talk about Susie Q 10x a day in marketing to understand how she is actually using the data). We still need humans to do this work to understand WHAT is actually happening with the data.

This means privacy pros need their time and their manager’s support, and it means no one in privacy can do this all by themselves. Well, unless you just want to make it all up, and most companies are thankfully honest and have integrity, so that plan doesn’t work.

In smaller companies, there is often one person who is going to be a main contact to help answer a LOT of your questions. Be nice to them. Buy them coffee and lunch. You want them as your new best friend.

It also means being thoughtful about timing. If you ask the product team the week before a launch, or drop it on everyone during their busiest season, you get rushed answers that are only half true.

The good news is that the inventory is a big project, but the ask of any one person is small. You need a little time from a lot of people. And because something in your company is always changing – a new tool here, a new use of data there – this is not a one-time thing.


The question I love asking

Somewhere in every inventory I get to ask my favorite question: How long do you keep this data?

The answers I hear most are “I don’t know” and “forever.” Forever is probably my most common answer, and that right there is the sign. If your answer is forever, either you don’t have a retention policy or you have one that isn’t working.

Here is what people underestimate. The data you keep forever is not free. The more data you have, the higher the risk if there is ever a breach. The more data stored, the higher the cost, because so many tools charge by user or by volume and have raised their prices as they add AI features.

The inbox nobody ever cleans out is a line item.

I will also say this. Coming up with a retention policy is the easy part, despite the hard part of the business most often wanting to keep the data forever.

Actually getting it deleted is truly the hardest part out there.


What a data inventory reveals

This is also where a gut check earns its keep. When teams fill out their own inventory, you get some remarkable answers. My favorite of all time was when a team was certain they collected biometric data during paid time off. On vacation. Most people are not handing over biometric data from a beach chair.

Marketing teams will almost always tell you they do not sell data, when a good part of ordinary marketing meets California’s definition of a sale. People are not trying to purposefully get this wrong; they just don’t know because they are not privacy experts.

That’s why data inventories need to be reviewed by privacy professionals (wahoo job security!). The privacy pro is reviewing for answers that make sense, asking, “Do we really do that?”, flagging sensitive data, determining whether it could be a sale of data, identifying a cross-border transfer situation, identifying when a privacy impact/risk assessment is needed, and more.

That last one has enough in it for its own class, which is why our next masterclass is on privacy impact assessments, or privacy risk assessments as CCPA calls them. Be sure to sign up for our Privacy Highlights newsletter and follow us on LinkedIn, so you don’t miss when we announce it!


It is more than a compliance project

A data inventory looks like a compliance exercise, and yes, if a regulator ever asks to see one, you will be very glad you have it. But the same document makes the business better.

I have watched an inventory raise questions like: Wait, why do I need 5 CRMs? Why do I need 3 of the same kind of system? Why do I need 2 survey tools? I have also watched it turn up data sitting in a tool the company forgot it was still paying for.

And if you are worried about shadow AI, our privacy data inventory over here is going to help you find it, because the minute you ask every team how they use data, the tools nobody approved come out of hiding.

A data inventory can help turn privacy from a cost center into a revenue center because managing data retention practices lowers cost and cutting redundant tools saves money.

A pro tip we covered in the masterclass: Use the language your company uses.

Who walks around saying “data subject?” No one other than people talking about GDPR all day. What is the vernacular you use in your company for customers – is it customers, clients, teachers, parents, travelers, advertisers, subscribers, patients, doctors, etc.

What about the data categories and data elements used? Tailor all of that to the common words that are used all the time in your company to make completing a data inventory simpler.


What was your aha?

At the end of every class, I ask everyone the same thing. What did you learn today? What is the one aha you are taking with you?

Last week, one person said she was going back to recheck all her website tracking and analytics, because so much has changed in the last year. Another said she realized how much more she needed to document, and who was responsible for what.

That is the whole point. Data inventories are huge, they are complex, and they are always changing, and if you walk away with even a few things that stick, that is a win.

So here is my question for you. What is your aha?

Wishing you a great week!

Jodi


💡 When you’re ready, here’s how we can help:

⚙ Privacy Advisory & Implementation: We help companies navigate privacy requirements with confidence. Our advisory support covers strategy, operations, and real-world implementation.

⚙ Fractional Privacy Services: We provide fractional privacy leadership tailored to your needs and pace. From program development to day-to-day support, we help you build and sustain a strong privacy program.

CONTACT US