Collect deliberately
List every field and event, including logs and analytics. Record the user-facing explanation and owner for the collection decision.
Data trail
A field on a screen can lead to identity services, analytics, email, support tools, hosting, backups, and human exports. The Estonia data trail names those paths before implementation and checks them again before release.
List every field and event, including logs and analytics. Record the user-facing explanation and owner for the collection decision.
Define which roles and vendors need each category, how access is granted, and how it is removed.
Map hosting, backups, integrations, support access, and transfers instead of relying on the location of the primary server alone.
Assign retention, correction, export, deletion, incident, and rights-response procedures with evidence that the action completed.
IDENTITYDo not collect registry, personal, or authentication details because an integration makes them available. Match the minimum identifier to the actual user task.
ANALYTICSDocument tags, cookies or local storage, events, destinations, consent choices, and retention. A marketing tool is still part of the product’s data route.
AI INPUTSIdentify what may enter an AI service, what must be redacted, whether outputs are stored, and who reviews the result before it affects a person.
RELEASEInspect production requests, access, logs, exports, and user controls. A diagram passes only when the deployed behavior matches it.