Workflow: Compliance Audit (GDPR/CCPA)

Identify and document all PII data to ensure compliance with GDPR, CCPA, HIPAA, and other regulations.

Step 1: Generate & Detect

Automated PII Scanning

Run the Data Dictionary generation with PII Detection Enabled. The AI will scan column names and sample values to identify sensitive data.

Scanning: customers.email
match found
Scanning: users.ssn
match found

Step 2: Review Findings

Verification Process

Navigate to the 'Review' page and filter by 'PII Only'. Verify categories, check high confidence scores, and remove any false positives manually.

Step 3: Create PII Inventory

CategoryTablesCompliance Impact
Email Addressescustomers, users, contactsGDPR Art. 30
Namescustomers, users, employeesGDPR Art. 30
Phone Numberscustomers, contactsGDPR Art. 30
Addressescustomers, shippingGDPR Art. 30
Financial Datapayments, transactionsPCI DSS
Health Datapatient_recordsHIPAA

Step 4-5: Map Activities & Rights

Processing Activities

Activity: Marketing
PII: Email, Name
Basis: Consent
Retention: 2 years
Recipients: ESP

Data Rights

  • Access: Query by ID
  • Erasure: Hard/Soft delete workflow
  • Portability: JSON export available

Step 6: Compliance Report & Controls

Generate Report

Export the full dictionary as a PDF. Includes PII inventory, processing activities, and retention policies.

Implement Controls

Use findings to implement access controls, encryption (at rest/transit), and automated retention policies.

Success Criteria

  • Complete PII inventory documented
  • GDPR Article 30 requirements met
  • Data Subject Rights procedures documented
  • Compliance report ready for audit