Data mapping table tracing one online journey from signup to deletion. How to map where your personal data goes online
Image: Privacy Notes

Guides

Part of Personal data privacy guide: collection, use, sharing, retention, security, deletion, and accountability

How to map where your personal data goes online

Trace one activity from the form you fill in to the copies left in vendors, backups and connected accounts, and test what deletion actually removes.

What to take away

  • Map one bounded activity, such as an order or a signup, not your whole online life.
  • Keep three columns apartwhat you saw, what you concluded, what you still do not know.
  • Count observed signals as well as submitted onesdevice identifiers, timestamps, location.
  • Follow copies into vendors, email receipts, backups, autofill and connected accounts.
  • Test one control at a time and record what changed, how fast, and what stayed visible.

A personal data map records where information starts, where it goes, and what you can do about it. It will not show every server or undisclosed practice. Its value is a disciplined view of the evidence you actually hold.

Pick one journey and give it an end

Choose a task with a clear beginning and a clear finish:

Pick one journey

  • registering for a streaming account
  • ordering an item
  • posting a photograph
  • tracking a workout
  • joining a video call
  • asking a smart speaker a question

Write down the start event and the outcome you wanted. A narrow scope keeps the map usable and makes the missing pieces easier to spot.

Build the table before you collect anything

Build the table

StepDataSourceRecipient or systemPurpose statedRetention clueControlEvidence
SignupEmail addressYouAccount systemCreate accountNotice unclearChange addressSignup form
CheckoutDelivery addressYouStore and carrierDeliver orderOrder-history settingEdit before shipmentReceipt

Keep passwords, recovery codes, full card numbers, identity documents and private message contents out of the map. Write category labels instead.

List what you hand over on purpose

Walk through these areas:

What you hand over on purpose

  • Forms
  • Profile fields
  • Uploads
  • Messages
  • Searches
  • Purchases
  • Support requests
  • Connected-device inputs

Capture the notice shown at collection and the date you saw it. A notice posted today may not describe a transaction from three years ago, so keep dated evidence when the history matters.

Add what the service observes

Data collected without typing includes device identifiers, IP address, and precise or approximate location. It also includes timestamps, browser properties, app events, and clicks. It further includes viewing history and transaction metadata. Look in permission menus, browser site controls, privacy dashboards, downloaded archives and receipts.

Data observed without typing

  • Device identifiers
  • IP address
  • Precise or approximate location
  • Timestamps
  • Browser properties
  • App events and clicks
  • Viewing history
  • Transaction metadata

A permission is not proof of use. "Camera allowed" means the app may reach the camera under platform rules. It does not show when the camera opened or whether it ever did.

Name the connected parties

List these items you can see in the evidence:

Connected parties to name

  • Account provider
  • Payment processor
  • Delivery company
  • Cloud host
  • Analytics provider
  • Advertising service
  • Identity provider
  • Support platform

The NIST Privacy Framework resource repository groups supporting material under outcomes that include inventory and mapping, risk assessment, governance and protection. That is a reason to look past a single database. It does not reveal any one service's undisclosed recipients.

Mark what was worked out about you

A service may calculate a fraud score, a recommendation, an interest category, a route, a ranking or a health trend from other information. Label these inferred unless the service confirms the method and the inputs.

Observed, inferred, unknown labels

Observed

Evidence
Archive contains it
Example
Recommendation category
Use
State as fact

Inferred

Evidence
May have shaped it
Example
Browsing history
Use
Label as inference

Unknown

Evidence
Inputs and weighting
Example
Method not confirmed
Use
Mark as unknown

Keep the three labels separate:

Mark what was worked out

  • Observed:the archive contains a recommendation category.
  • Inferred:browsing history may have shaped it.
  • Unknown:the inputs and their weighting.

That wording stops the map from claiming more than the evidence supports.

Follow the copies

Check account archives, cloud storage, synced devices, and email receipts. Also check downloaded files, browser autofill, and password managers. Then check photo backups, calendars, and support attachments. A record can outlive the place you changed it.

Note the form each copy takes:

  • active profile
  • transaction history
  • security log
  • backup
  • public post
  • shared message
  • local export Each one has its own retention and its own control path.

Record the controls and the rights

Find the settings for profile visibility, permissions, advertising, history and connected apps.
Find the settings for downloads, correction, account closure and deletion. Write down the menu path and the date you checked, because products move.

A preference is not a legal request. Turning off personalized ads can change which ads appear without deleting the history underneath. Closing an account may start a retention period rather than erase records the same day.

Run tests that cannot hurt you

Change a noncritical profile field, revoke a permission you no longer use, disconnect an old integration, or request an archive. Record what changed, how quickly, and where the old value stayed visible.

Skip tests that could lock you out or destroy records you need. Before any deletion, save receipts, licences, tax records, evidence of abuse and recovery information you have a real reason to keep.

Turn the gaps into questions

Send the provider a short list:

  • Which recipients receive precise location?
  • How long do failed-login logs stay?
  • Does account deletion cover uploaded files and derived profiles?
  • How are backup copies retired?
  • Can one inference be corrected or challenged?

Keep the reply with the map. Update it after a major change of settings, device, provider or account.

Common questions

Can a personal map show every company holding my data?

No. It documents visible evidence and known recipients. Undisclosed transfers, internal systems and stale copies stay outside it.

Should I use a spreadsheet?

A spreadsheet works, but secure it. The map itself reveals services, habits, identifiers and relationships.

Does a downloaded archive show deleted data?

Not necessarily. It shows what the provider chose to include at that moment, not every operational, backup, security or legally retained record.

How often should the map be updated?

Review it after major account, device, permission, service or policy changes, and whenever a new recipient appears.

More in Guides

Latest from Guides Desk