A privacy team has built a data flow map that traces customer personal information from a web sign-up form, through an internal database and an analytics warehouse, and out to a third-party email vendor. Leadership asks what this flow map, specifically, contributes to the information management programme that the team's other artefacts do not. Which TWO purposes does the data flow map most directly serve? (Select TWO.)
- AIt assigns each category of personal information to a sensitivity tier so that handling controls scale with the data's risk.
- BIt records a disposal trigger and retention period for each category so records are deleted once they are no longer needed.
- CIt shows how and where personal data moves between systems and out to third parties, exposing undocumented or unexpected transfers. Correct
- DIt serves as the authoritative catalogue of every category of personal information the business holds and names the owner accountable for each.
- EIt locates the points where data crosses to other processors or jurisdictions, helping the team assess onward and cross-border transfer risk. Correct
Why A is wrong: Assigning sensitivity tiers is the job of a data classification scheme, not a flow map, so this purpose belongs to a different artefact.
Why B is wrong: Tying categories to disposal triggers and retention periods is the function of a records retention schedule, which a flow map does not perform.
Why C is correct: Tracing movement between systems and to external recipients is the core purpose of a flow map and is exactly how hidden transfers surface.
Why D is wrong: Cataloguing what categories exist and assigning ownership is the role of the data inventory, so this describes the inventory rather than the flow map.
Why E is correct: By plotting each hand-off along the data's journey, the flow map highlights onward and cross-border transfer points where risk must be assessed.