This article appeared in Cybersecurity Law & Strategy, an ALM publication for privacy and security professionals, Chief Information Security Officers, Chief Information Officers, Chief Technology Officers, Corporate Counsel, Internet and Tech Practitioners, In-House Counsel. Visit the website to learn more.

In the current digital era, businesses are gathering and keeping enormous volumes of data on their clients, staff and operations. Data breaches and cyberattacks are more likely as data volume increases. Corporate legal departments must implement an efficient information governance procedure that incorporates data mapping to reduce these risks. Data mapping is the process of figuring out what information a company gathers, where it is kept and how it moves across the company. Every company's legal department should engage in it since it enables them to comprehend their data landscape and put the necessary security measures in place to safeguard sensitive data. This article examines the importance of data mapping for corporate legal departments and how it fits into a larger strategy.

|

Familiar Ways That Data Mapping Engages In Your Everyday Matters

We all know that data mapping is the process of identifying and documenting the flow of data through a system or organization. In litigation or regulatory cases, data mapping can help identify and locate relevant data sources, understand the scope of data retention obligations and assess the risks associated with data storage and management practices. Here are some familiar ways that data mapping is involved in litigation and regulatory cases:

|
  1. Securities Fraud Investigation. In a securities fraud investigation, data mapping can help identify all the systems and applications that may contain relevant data, such as trading systems, customer databases and email archives. Data mapping can also aid in picking out the individuals with access to this data and the specific elements relevant to the investigation.
  2. E-Discovery. In e-discovery, data mapping can help identify the locations of electronically stored information and determine the best approach for collecting, processing and reviewing that ESI. This can include mapping the data flow within an organization to find key custodians and data repositories and tracking the data processing and review workflows to ensure that relevant data is identified and produced promptly and efficiently.
  3. Privacy Compliance. In a privacy compliance audit or investigation, data mapping can help identify the types of personal data that an organization collects, where that data is stored, how it is processed and who has access to it. This can assist organizations in uncovering potential compliance risks and developing strategies for minimizing those risks, such as implementing data minimization and deletion policies.
  4. Intellectual Property Litigation. In intellectual property litigation, data mapping can help identify the locations of key documents, such as patents, trademarks and copyrights, as well as the systems and applications used to create, store and manage those documents. This can aid in determining potential sources of infringement or misappropriation and potential weaknesses in an organization's intellectual property management practices.
  5. Anti-Money Laundering Compliance. In an anti-money laundering investigation, data mapping can help identify the locations of financial transaction data, such as bank records and wire transfer logs, as well as the systems and applications used to manage that data. This can allow investigators to trace the flow of funds through an organization and establish potential money laundering activities.

Data mapping has become increasingly important in recent years as more companies collect and process substantial amounts of personal data. Failure to properly map and protect data can lead to legal repercussions, including fines, penalties and legal liability.