In today's era of strong digitalization, personal data has become a valuable asset but also full of risks for organizations and businesses. With the rise of data breaches and stricter legal regulations, protecting personal information is no longer an option but a mandatory obligation. One of the most important tools for achieving this compliance is Data Mapping – also known as data mapping. Data Mapping not only helps organizations understand their "data panorama" but also serves as a foundation for the implementation of legal requirements for personal data protection globally, especially those from regulatory agencies.

In this article, we will analyze in depth the role of Data Mapping in international and Vietnamese legal frameworks, and analyze its benefits in the realization of data subject rights, impact assessment, and risk management.
Understanding data mapping
Data Mapping is "a detailed map that shows how personal information is stored, processed, and transferred within an organization."[1] This process involves building a data inventory and drawing a data map, which helps the organization track data from collection to destruction. In the context of legal frameworks such as the European Union's (EU) GDPR (General Data Protection Regulation), [2]Singapore's PDPA (Personal Data Protection Act)[3] and China's PIPL (Personal Information Protection Law) increasingly emphasizing the responsibility for transparency and confidentiality, Data Mapping has emerged as an effective method. helping to mitigate risks and ensure compliance of businesses and organizations as data collectors and/or processors.
Data Mapping is the process of collecting and documenting details about how personal data is managed in an organization. It starts with creating a data inventory – a list of all available personal data, including the type of data, the source of collection, the location where it is stored, and the purpose of use. Then, the organization draws a data map to illustrate the flow of data between departments, systems, or third parties. The process is usually broken down into specific steps.
First, identify the data source.
The organization needs to list all the places where personal data is stored, from electronic databases, software systems, or from paper documents to employee devices. This step ensures that no source is missed, which helps to avoid potential security vulnerabilities.
Second, data classification.
Based on sensitivity and purpose of processing, data is grouped, such as public, sensitive, or important information. This classification helps organizations prioritize the protection of higher-risk data types.
Third, record the data flow.
This is an important step, where the organization draws a diagram that illustrates the stages of data going through such as from collection, storage, use, sharing to destruction. The diagram also recognizes the parties involved at each step, such as internal departments or external partners.
Fourth, identify data subjects and data storage and processors.
This process recognizes the individuals involved (customers, employees, other stakeholders) and organizations that are either data collectors, archivers or data processors, ensuring the clear responsibilities of each party throughout this process.
Finally, gather additional information.
Include details such as data fields, formats, retention criteria, and deletion periods. By maintaining and continuously updating data inventory and data maps, the organization achieves a clear view of its data, laying the foundation for other legal compliance activities. We believe that Data Mapping is not only a technical tool but also a comprehensive risk management strategy that every business needs to have in the current context.
Data mapping in the international legal framework
EU GDPR
The GDPR, which has been in place since 2018, is one of the strictest legal frameworks for personal data protection. Article 30 of the GDPR requires organizations to create Records of Processing Activities (RoPA). This is a detailed record of all personal data processing, including the type of data, the purpose of the processing, the legal basis, the retention period and the recipients. Data Mapping directly supports the creation and maintenance of RoPA by mapping the data flow, which helps the organization track and document all necessary processing activity.
The UK's Information Commission Office (ICO) instructs that organisations should conduct information audits and create data flow diagrams to clearly understand "what personal data is being processed, who is processing it and where".[5] This not only satisfies legal requirements, but also supports the exercise of data subjects' rights, such as the right to access, rectify, erase or restrict processing. When receiving a request for data, data maps help quickly search and collect relevant information, reducing response times from weeks to just a few days.
In Article 35 GDPR, the first step is to define and map data flows for risk assessment. Data mapping helps companies respond to personal data access requirements faster and support DPIA more effectively. In terms of security, understanding the data flow diagram allows for the implementation of technical measures that are appropriate to the level of risk. When a data breach occurs, Data Mapping helps determine the scope of impact, decide to report to agencies and subjects in a timely manner.
Although the GDPR does not directly require "data mapping", EU authorities such as the ICO and the EDPB (European Data Protection Board) strongly recommend this. Many large enterprises in the EU use automation tools to collect inventory and create data maps, ensuring continuous and strict compliance with the regulations of the GPDR and UK law.

Source: EDPS
Singapore's PDPA
The PDPA is not mandatory to maintain RoPA like the GDPR, but the Personal Data Protection Commission of Singapore (PDPC) recommends that organisations catalog personal data. In the "Personal Data Management" guide, step 2 is "Map Out Your Personal Data Inventory", which maps out all personal data, documenting the cycle from collection to destruction, including where and how it is collected, the level of consent, the purpose and how it is used.
The role of a Data Protection Officer (DPO) in Singapore includes preparing or guiding the creation of a personal data inventory. In DPIA, PDPC requires mapping the flow of data through the processing stages. Although there are no specific provisions, the lack of data flow management will make it difficult to ensure compliance with obligations such as intent notification and adequate retention.
Data Mapping supports adherence to principles such as purpose limitation, transparency, and security. When it is necessary to notify the subject or provide data according to the access request, inventory and diagrams help to answer completely. In a data breach, it determines the response process.
The PDPC provides guidance such as the "DPIA Guide" (2021), which illustrates how to identify and map data touchpoints. In the "Guidelines for the Use of Personal Data for AI" (2023), PDPC recommends applying Data Mapping to track AI training data sources, supporting unauthorized access assessment.
In fact, in the ruling against Eatigo (2022), PDPC emphasized that maintaining an accurate personal data asset inventory is a premise for complying with the law on personal data protection. The lack of a list of data contributes to sanctioned violations. In 2023, many organizations were fined for over-processing data, often related to a lack of data inventory.
China's PIPL
PIPL does not directly provide for data mapping, but it does mandate the implementation of a Personal Information Security Impact Assessment (PIIA) in high-risk cases, such as large-scale processing of sensitive data or cross-border transfers. PIIA results and processing records must be kept for at least 3 years. According to the GB/T 39335-2020 standard, the first step is a comprehensive survey, data cataloging and data mapping diagram.
PIPL requires periodic record-keeping and audits. Organizations often build data inventory, classify data (general, important, especially important), and map out the processing flow to meet it. Data mapping helps determine the scope of processing and risk, especially before transferring data overseas.
In PIIA, Data Mapping enables the identification of sensitive and large-scale data, deciding whether an assessment is mandatory. When data is leaked, it helps to quickly assess the scope of impact.
Agencies such as TC260 promulgate the "Personal Information Security Code" (GB/T 35273) and "PIIA Guidelines" (GB/T 39335) standards, which require data classification and flow diagrams. CAC guidelines on data transfers, which require detailed records. TrustArc notes PIPL requires maintaining a record of processing activity, including data classification.
Vietnam with the Personal Data Protection Law (PDPL)
Similar to China, Singapore, and EU laws, although the PDPL does not directly stipulate "data mapping", it does require organizations to conduct data mapping to determine the type of personal data, classify them into general or sensitive information, and draw a data flow diagram to assess risks. This is the basic preparation step, help organizations understand how data flows in and out of the system, thereby ensuring compliance with principles such as purpose limiting, data mitigation, and security.
Data Mapping serves as the foundation for the Data Protection Impact Assessment (DPIA) and the Data Transfer Impact Assessment (DTIA), which must be submitted within 60 days of the initiation of data processing or transfer. Data Mapping helps identify data flows, assess vulnerabilities, and support periodic assessment updates (every 6 months or when business operations change). Small organizations and startups may be exempt from DPIA for the first 5 years if they do not process sensitive or large-scale data. In addition, it supports the appointment of a person in charge of personal data protection (DPO), documenting the processing and responding to data breaches so that it can be notified for 72 hours if it affects national or personal security.
Our practical experience shows that the Department of Cyber Security and High-tech Crime Prevention and Control (A05), Ministry of Public Security, when evaluating DPIA and DTIA documents, one of the requirements that businesses must provide in the dossier is data mapping.
Data Mapping is an effective and essential way to comply with personal data protection laws, from GDPR and PDPA to PIPL and PDPL, by providing clear visibility, support for logging, risk assessment, and incident response. Organizations and businesses should build a continuous and updated Data Mapping process that is suitable for their business. This is an effective way to reduce risks and increase trust from data subjects. However, to be able to be data mapping is not a simple matter. This requires individuals and units who are knowledgeable about the law on personal data protection and business activities, especially the company's data collection, storage and processing.
Lawyer Nguyen Van Phuc
HM&P Law Firm
[1] https://www.osano.com/articles/data-mapping, accessed on 2025/09/23
[2] https://gdpr-info.eu/, accessed on 2025/09/23
[3] https://sso.agc.gov.sg/SL/PDPA2012-S63-2021, accessed on 2025/09/23.
