data.day

The Two-Column Data Inventory That Saves Weeks Later

When a Subject Access Request arrives, chaos is expensive. We propose a simple, elegant inventory that turns a legal panic into a routine administrative task.

The Chaos of the Unmapped Estate

It happens on a Friday afternoon. An email arrives with the subject line: “Subject Access Request.” A former client wants to know exactly what data you hold on them, why you have it, and who you shared it with. They want a copy. You have 30 days.

Does your pulse quicken? Do you feel a tightness in your chest?

If you feel panic, it is because you have failed the first rule of data stewardship: You do not know what you possess. You have allowed data to sprawl like ivy across your infrastructure—into Dropbox, into Slack, into the personal downloads folder of an intern who left three months ago.

This is sloppy. C’est ridicule.

Imagine a bank that could not tell you which vault your diamonds were in. You would not trust them. Why, then, do we expect our clients to trust us when we treat their digital identity like loose change scattered in sofa cushions?

The Liability: The Cost of the Scramble

When you do not have a map, every request becomes an excavation.

You burn billable hours searching for files. You risk missing a sensitive document that later surfaces in a lawsuit. You annoy your IT staff. This inefficiency is a tax on your lack of discipline.

[Image of a chaotic network diagram showing disconnected data silos versus a streamlined, linear data flow chart]

The “We’ll figure it out when asked” strategy is not a strategy. It is a gamble. You are betting that no one will ask. But in this era of privacy awareness, everyone is asking. The cost of this chaos is not just financial; it is reputational. If you take 29 days to find a file that should take 20 minutes to retrieve, you have signaled incompetence.

The Safeguard: The Two-Column Fix

The solution is not to buy a $50,000 enterprise governance platform. The solution is a piece of paper (or a secure shared document) with two columns.

Column A: The Asset (What) Column B: The Reason (Why)

  • Asset: Client Intake Form (Typeform). Reason: Project initiation.
  • Asset: Newsletter List (Mailchimp). Reason: Monthly updates (Consent given).
  • Asset: Billing Details (Xero). Reason: Statutory tax requirement.

This is the Living Inventory.

It forces you to confront the reality of your data estate. When you try to fill in Column B and realize you cannot explain why you have a folder full of passport scans from 2019, you realize it is time to delete.

This inventory turns a frantic search into a routine lookup. When the request comes, you open the list. You know exactly where to look. You export the data. You redact. You send.

Voilà.

Peace of mind is not a product of luck. It is a product of preparation. Map your data today, so you do not have to dig for it tomorrow.

FAQs

Do we need to list every single email?

No. You list the *systems* where the emails live. You map the container, not the contents.

Is this inventory a one-time project?

Data is alive; it moves. If your inventory is a static PDF from 2022, it is already a lie. It must be a living document.

Can't we just use a discovery tool to find the data later?

You can, but that is like waiting for a fire to start before buying an extinguisher. Prevention is cheaper than remediation.