A privacy notice is easier to write accurately when the company understands its data flows. Start with what the product and team actually do, including analytics, support tools and supplier services.

This guide helps prepare the facts. It does not decide which privacy laws apply or establish compliance.

Follow one person's journey

Choose a real product flow: a user registers, uploads information, contacts support and closes an account. Record what data appears at each step, why it is used and where it goes.

Then review less visible flows: logs, backups, billing, marketing, employee records and test environments. Identify whether data about other people arrives through a customer rather than directly from the individual.

Create a usable data inventory

For each flow, record categories of people and data, purpose, source, systems, recipients, locations and retention. Identify an owner who can confirm the facts.

Mark unknowns rather than filling them with assumptions. If engineering cannot explain whether a supplier retains prompts, that is an open issue to investigate, not a detail to omit from the map.

Connect the map to communications

For Australian businesses, first check Privacy Act coverage. OAIC guidance says most small businesses are not covered, but some are; turnover alone does not answer every case. OAIC small-business coverage.

For APP entities, the Australian Privacy Principles address privacy policies and collection notices as well as use, disclosure and security. OAIC APP overview. Use the map to prepare accurate explanations; do not infer compliance from a copied policy.

Give the map to a qualified adviser so roles, notices, consents and contractual arrangements can be assessed in context.

Check that operations match the explanation

Ask how the team handles requests, restrictions, retention and account closure. Identify the systems needed to locate and act on data. Do not promise deletion timelines or locations that the company cannot support.

For a support ticket, for example, check whether copies remain in email, a ticket platform and a product log. The data map should make those paths visible.

Keep it current

Review the map when you add an integration, launch a new feature, change a supplier or enter a new market. Assign someone to record the change and trigger review.

Read data-processing agreements for supplier and customer contracts, and AI product legal review for prompt and model workflows.

General information for planning a conversation with qualified advisers. It is not legal advice for your circumstances. Scope, jurisdiction and fees are agreed before any engagement.