Data flow

See how personal data moves between your systems, vendors and other parties for each processing activity, including where it crosses borders.

A data flow shows how personal data moves for a specific business purpose: which systems and parties receive it, and where they're located. Data flows make it easy to explain a processing activity at a glance, spot data leaving your main region, and show auditors and regulators how data actually travels through your organization.

Before you start, make sure your processing activities are set up and linked to their data sources. See Map business purposes with processing activities.

What a data flow shows

ElementWhat it represents
Data sourcesThe systems in your inventory linked to the processing activity. They're included automatically.
Other entitiesParties outside your inventory that receive or provide data, such as government agencies, partners, or paper-based processes
DirectionWhether each party is an origin of the data, a receiver of it, or both
LocationsWhere each party is based, so you can see when data crosses borders

📸 [IMAGE: Data flow diagram for a processing activity]

Open a data flow

  1. In the left navigation, under Data mapping, select Processing activities.
  2. Open a processing activity.
  3. Scroll to the Data flow section. [confirm location on the current processing activity page]

Every data source linked to the processing activity appears in the data flow automatically, as a Receiver by default.

Build out a data flow

  1. In the Data flow section, review the data sources included automatically.
  2. Set each one's role, for example whether it's where the data originates or where it's sent. [confirm options]
  3. Add any other entities involved, such as an agency, a partner or an offline process. [confirm how to add an entity]
  4. Save your changes.

📸 [IMAGE: Adding an entity to a data flow]

When website scanning finds new third-party systems collecting data on your website, they're added to your inventory along with their locations, and your data flows update to reflect them. [confirm: still applies]

Use data flows to spot transfers

Many privacy laws worldwide restrict or set conditions on transferring personal data across borders. Data flows show each party's location, so you can quickly see when a processing activity sends data outside your main region.

When you spot a transfer, you can:

Tips

  • Complete your processing activities first. Data flows are only as accurate as the data sources linked to each activity.
  • Keep vendor locations current. Vendor scout can fill in hosting locations automatically. See Research Vendors with Mira AI (Vendor Scout).
  • Add the parties you don't manage, such as regulators or payroll providers. They often matter most for transfers.

Related articles


Did this page help you?