Map activities, not information or data flows
You should map activities (instead of information, data flows or processes) as a first step to complying with data protection laws (like the GDPR and the Protection of Personal Information Act (POPI Act)). The law requires larger organisations to create [...]