Skip to main content
Data protectionEuropeJune 3, 20266 min

GDPR and 152-FZ: a data review map

How product and operations teams can check roles, legal bases, vendors, and cross-border data flows.

Abstract map of personal data flows across jurisdictions and systems without text or logos

When a product handles users, employees, contractors, or B2B customers across jurisdictions, data review should not start with a privacy policy. It should start with the actual data flow: what passes through the product, who decides how it is used, and where the legal regime changes.

Map the data flow

Create a map of what data is collected, from which interface or contract, where it is stored, who has access, who receives it, how long it is kept, and how it is deleted. For a product team, it helps to separate user data, payment data, support, analytics, marketing, and HR.

At this stage, the goal is not to polish policy wording. The goal is to see the operating model. If the team does not know where data sits and which vendors receive it, the legal text will describe an intended model rather than the real one.

Check the company role

For each flow, define the role: does the company decide purposes and means, or does it process data on behalf of a customer? In B2B SaaS, the model can be mixed: the company may be a processor for customer end-user data and a controller for account, billing, and support data.

The role affects contracts, notices, response to data subject requests, security, and vendor transfers. A role error often leads to the wrong DPA, overbroad promises, or missing obligations.

Separate legal bases and consent

Not every data flow should rely on consent. Depending on applicable law and processing facts, different operations may rely on contract, legal obligation, legitimate interest, consent, or another basis. Consent is not always the easiest route because it must be collected correctly, stored, and honored if withdrawn.

Under GDPR and 152-FZ, special categories of data, marketing, cookies, analytics, cross-border transfers, and vendor processing need separate factual checks. These areas require precision, not a universal template.

Review vendors and transfer points

List CRM, analytics, cloud, email platforms, payment services, support tools, storage, and developers with access to production data. For each vendor, record the role, contract, processing location, security measures, subprocessors, and deletion process.

If data crosses borders, check more than the vendor's headquarters. Look at cloud region, support access, backups, analytics routing, and remote teams. Risk depends on the specific flow and the applicable transfer regime.

Minimum review pack

  • data map and system list;
  • privacy notice and consent texts;
  • DPA or processing agreements;
  • retention and deletion policy;
  • procedure for data subject requests;
  • list of cross-border transfers;
  • incident log and security owners.

This map does not answer every question automatically. It shows where processing is clear and where the conclusion depends on the company role, jurisdiction, data type, vendor, and actual transfer route.

Review the data map