| CPC G06Q 30/0609 (2013.01) [G06Q 10/063114 (2013.01); G06Q 10/0635 (2013.01); G06Q 50/265 (2013.01)] | 20 Claims |

|
1. A method comprising:
identifying, by computing hardware, a plurality of pieces of data across a plurality of data sources associated with a data subject in a data map;
determining, by the computing hardware, that the plurality of pieces of data comprise sensitive data;
determining, by the computing hardware, that a first portion of the sensitive data exactly matches privacy campaign data stored in a privacy campaign data record for a data processing activity; and
reconciling, by the computing hardware based on determining that the first portion of the sensitive data exactly matches the privacy campaign data, the plurality of pieces of data with a data flow for the data processing activity by:
determining whether each of the plurality of pieces of data is represented in the data flow;
in response to determining that at least one of the plurality of pieces of data is not represented in the data flow, updating the data flow by associating the at least one of the plurality of pieces of data with the data flow; and
defining, in the data flow, a privacy related attribute for the at least one of the plurality of pieces of data, the privacy related attribute including an indication of the data subject.
|