| name | privacy-data-flow-map |
| description | Map personal and sensitive data from collection through use, storage, logs, analytics, sharing, export, backup, retention, and deletion with purpose and ownership. |
Privacy Data Flow Map
Use when this procedure is the primary professional method needed for the assignment.
Procedure
- Confirm the decision or outcome this work must support, its scope, owner, constraints, and definition of success.
- Establish the evidence baseline using schemas, APIs, event catalogs, logs, vendors, storage, retention policies, and product flows. Do not fill material gaps with assumptions when they can change the result.
- Inventory fields and identifiers, trace system boundaries and subprocessors, capture purposes/legal-policy basis supplied by owners, and identify shadow copies or derived data.
- Exercise realistic edge, failure, transition, or exception cases that could invalidate the result; record unresolved uncertainty explicitly.
- Validate the output against the original outcome and any neighboring professional contracts so this skill does not silently absorb another specialist's authority.
- Record the resulting artifact, measurements, decisions, provenance, and handoff information needed for another owner to reproduce or continue the work.
Quality gate
Every material copy and transfer has a documented purpose, owner, retention/deletion path, and trust boundary.