7.4.1 Limit collection
The organization must limit collection of personal data to the minimum that is adequate, relevant, proportional and necessary for the identified purposes, including data collected indirectly through means such as web and
4
artefacts
1
held by a system
2
at each review
moderate
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Evidence optional collection is off by default, captured from the live configuration · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Assessment of indirectly collected data such as logs, telemetry and tracking · SIEM / log platform
- Periodic review of collection against current purposes · Document repository
governing documentDocuments that govern the control
- Field level justification linking each item collected to an identified purpose · Document repository
First move
Start with the 1 of 4 artefacts that already live in a system (Cloud console / configuration management); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Justification performed for form fields while telemetry, cookies and logs collect far more without review
- Optional processing enabled by default with an opt out, which reverses the required default
- Fields collected because they might be useful later, which is not a purpose
- Legacy fields retained in collection long after the purpose that justified them ended
- Default configuration correct at launch and drifted since, with no verification
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet