Data inventory and classification
Data held is inventoried, classified and assigned an owner.
DTCF normalises what an organization must achieve into 11 objectives across 10 families, then maps each to the frameworks practitioners face. Mappings are graded: fully addressed, partially addressed, or deliberately absent with the reason recorded. An empty cell is a finding about the framework, not a gap in your programme.
DTCF 2026.1 · published 10 Sep 2026 · CC BY 4.0 · free to use with attribution
Data held is inventoried, classified and assigned an owner.
Personal data is processed on a stated basis, limited to what is needed and kept only as long as needed.
Data leaves the organization only through a decided channel, with a defined end and a record of what was shared.
Data is removed from primary systems, backups, caches, exports and third parties when it is no longer needed or on request.
Third parties with access to data or systems are inventoried with an owner and a criticality judgement.
Third parties are assessed before onboarding and periodically thereafter, at a depth proportionate to what they touch.
Contracts carry security, privacy and breach terms, and access and data are recovered when the relationship ends.
Reportable incidents are assessed and notified to regulators and affected people within the applicable deadlines.
Backups exist, are protected from the same failure as production, and restoration is tested.
People affected by automated decisions are told, and a competent person can intervene.
Evidence shows what was done, by whom and when, and is kept for the period the obligation requires.
First edition. Objectives are normalised statements of what an organization must achieve. Mappings are graded: full, partial, or a recorded absence with the reason it is absent. An empty cell is a finding about the framework, not about the objective.
Framework names and references are the property of their publishers. DTCF is an independent mapping and is not endorsed by them. Corrections are welcome through the contact form and are published in the edition changelog.