
Guides
How to map where your personal data goes online
Trace one activity from the form you fill in to the copies left in vendors, backups and connected accounts, and test what deletion actually removes.
What to take away
- Map one bounded activity, such as an order or a signup, not your whole online life.
- Keep three columns apartwhat you saw, what you concluded, what you still do not know.
- Count observed signals as well as submitted onesdevice identifiers, timestamps, location.
- Follow copies into vendors, email receipts, backups, autofill and connected accounts.
- Test one control at a time and record what changed, how fast, and what stayed visible.
A personal data map records where information starts, where it goes, and what you can do about it. It will not show every server or undisclosed practice. Its value is a disciplined view of the evidence you actually hold.
Pick one journey and give it an end
Choose a task with a clear beginning and a clear finish:
Pick one journey
- registering for a streaming account
- ordering an item
- posting a photograph
- tracking a workout
- joining a video call
- asking a smart speaker a question
Write down the start event and the outcome you wanted. A narrow scope keeps the map usable and makes the missing pieces easier to spot.
Build the table before you collect anything
Build the table
| Step | Data | Source | Recipient or system | Purpose stated | Retention clue | Control | Evidence |
|---|---|---|---|---|---|---|---|
| Signup | Email address | You | Account system | Create account | Notice unclear | Change address | Signup form |
| Checkout | Delivery address | You | Store and carrier | Deliver order | Order-history setting | Edit before shipment | Receipt |
Keep passwords, recovery codes, full card numbers, identity documents and private message contents out of the map. Write category labels instead.
List what you hand over on purpose
Walk through these areas:
What you hand over on purpose
- Forms
- Profile fields
- Uploads
- Messages
- Searches
- Purchases
- Support requests
- Connected-device inputs
Capture the notice shown at collection and the date you saw it. A notice posted today may not describe a transaction from three years ago, so keep dated evidence when the history matters.
Add what the service observes
Data collected without typing includes device identifiers, IP address, and precise or approximate location. It also includes timestamps, browser properties, app events, and clicks. It further includes viewing history and transaction metadata. Look in permission menus, browser site controls, privacy dashboards, downloaded archives and receipts.
Data observed without typing
- Device identifiers
- IP address
- Precise or approximate location
- Timestamps
- Browser properties
- App events and clicks
- Viewing history
- Transaction metadata
A permission is not proof of use. "Camera allowed" means the app may reach the camera under platform rules. It does not show when the camera opened or whether it ever did.
Name the connected parties
List these items you can see in the evidence:
Connected parties to name
- Account provider
- Payment processor
- Delivery company
- Cloud host
- Analytics provider
- Advertising service
- Identity provider
- Support platform
The NIST Privacy Framework resource repository groups supporting material under outcomes that include inventory and mapping, risk assessment, governance and protection. That is a reason to look past a single database. It does not reveal any one service's undisclosed recipients.
Mark what was worked out about you
A service may calculate a fraud score, a recommendation, an interest category, a route, a ranking or a health trend from other information. Label these inferred unless the service confirms the method and the inputs.
Observed, inferred, unknown labels
Observed
- Evidence
- Archive contains it
- Example
- Recommendation category
- Use
- State as fact
Inferred
- Evidence
- May have shaped it
- Example
- Browsing history
- Use
- Label as inference
Unknown
- Evidence
- Inputs and weighting
- Example
- Method not confirmed
- Use
- Mark as unknown
Keep the three labels separate:
Mark what was worked out
- Observed:the archive contains a recommendation category.
- Inferred:browsing history may have shaped it.
- Unknown:the inputs and their weighting.
That wording stops the map from claiming more than the evidence supports.
Follow the copies
Check account archives, cloud storage, synced devices, and email receipts. Also check downloaded files, browser autofill, and password managers. Then check photo backups, calendars, and support attachments. A record can outlive the place you changed it.
Note the form each copy takes:
- active profile
- transaction history
- security log
- backup
- public post
- shared message
- local export Each one has its own retention and its own control path.
Record the controls and the rights
Find the settings for profile visibility, permissions, advertising, history and connected apps.
Find the settings for downloads, correction, account closure and deletion. Write down the menu path and the date you checked, because products move.
A preference is not a legal request. Turning off personalized ads can change which ads appear without deleting the history underneath. Closing an account may start a retention period rather than erase records the same day.
Run tests that cannot hurt you
Change a noncritical profile field, revoke a permission you no longer use, disconnect an old integration, or request an archive. Record what changed, how quickly, and where the old value stayed visible.
Skip tests that could lock you out or destroy records you need. Before any deletion, save receipts, licences, tax records, evidence of abuse and recovery information you have a real reason to keep.
Turn the gaps into questions
Send the provider a short list:
- Which recipients receive precise location?
- How long do failed-login logs stay?
- Does account deletion cover uploaded files and derived profiles?
- How are backup copies retired?
- Can one inference be corrected or challenged?
Keep the reply with the map. Update it after a major change of settings, device, provider or account.
Common questions
Can a personal map show every company holding my data?
No. It documents visible evidence and known recipients. Undisclosed transfers, internal systems and stale copies stay outside it.
Should I use a spreadsheet?
A spreadsheet works, but secure it. The map itself reveals services, habits, identifiers and relationships.
Does a downloaded archive show deleted data?
Not necessarily. It shows what the provider chose to include at that moment, not every operational, backup, security or legally retained record.
How often should the map be updated?
Review it after major account, device, permission, service or policy changes, and whenever a new recipient appears.







