Execute a detailed data Inventory and discovery
Identify the differents kinds of personal data you collect
When/Where it is collected from?
How do you use it?
How/Who do you share it with?
Map your data flows.
Point of data collection.
Touch points shall include sub-processors.
Storage, Retention, Deletion.
Processing (including also internal systems, service providers such as AWS).
Mapping is key to successful implementation (stored/in transit data).
Report in documentation.
Data flow summary and visuals (useful for understanding and awareness within departments).
Third party integration agreements.
Not feasible manually for most companies, you might need automation solution to rely on a dynamic map of your data (inventory, discovery, current activity and history) with tracking tool necessary for monitoring (access, transfers, correction, erasure).
The data inventory will facilitate the classification of data.