Data Map

Getting started with your Data Map.

A visual inventory of where personal data lives in your business and how it flows, so you can find it, classify it, and account for it.

What the Data Map is

The Data Map is a picture of your data: where it comes in, where it is stored, who processes it, and where it goes out. You build it as a node-and-edge graph, and the same map is available as a table when you would rather work from a list. The two views stay in sync.

A current map is what lets you find a person's data when a request comes in, and account for what you collect, store, and share when a regulator or a registration form asks.

Build your map

Open ai.trustsuperset.com/data-map. You do not have to draw the whole thing by hand.

  • Import and let the AI map it. Click Import Data Flow and upload a CSV of your processing activities, or pull from Vanta (your subprocessor list), Google SSO (the apps you have authenticated into), or GitHub. Superset's AI reads what you import and lays out a first-draft map: the nodes it found and how they connect, based on how subprocessors usually fit into a flow. It gets you most of the way from a blank canvas. Reconnect or adjust the few it misses.
  • Add nodes by hand. Drag a node from the Node Library onto the canvas, or use Add New Row in the table view, then name it and connect it.

Those connections reach more than 1,400 systems, so Superset can find where your data lives without you cataloging every tool by hand. Importing adds to your map without touching nodes you already have.

The five node types

Each node is one of five types that describe how data moves through your business:

  • Data Source Where personal data originates.
  • Process A transformation or business process applied to the data.
  • Subprocessor A third party that handles the data for you.
  • Data Store Where data sits at rest.
  • Data Share/Sale Where data leaves your environment.

Tag and connect

Two things make the map useful:

  • Tag each node. Every node carries four tag categories: Geography, Sensitivity, Purpose, and Access Level (for example: EU, PII, Analytics, Restricted). Tagging lets you filter and audit the map by data type, sensitivity, purpose, and region.
  • Connect the flow. Link nodes with Receives From and Sends To so the map shows how data actually moves. Use Auto-Layout to arrange the graph once you have a few nodes in place.

For your information

Keep it current A data map only helps if it stays current. When you add a system, a subprocessor, or a new data share, update the map so it still answers the questions you built it for. You can re-import at any time, and changes you make in either view show up in the other.
Welcome to Superset If anything in this guide doesn't behave the way it says, email [email protected] and we'll dig in.