Personal Data Dictionary

The Personal Data Dictionary is an inventory of every personal data type your organization processes. Where your Records of Processing Activities (RoPA) answers “what processing activities do we run,” the dictionary answers the prior question: “what data do we actually hold?” Think of it as the entity-level layer below the RoPA — each entry represents a named data type (email address, salary, health data) and links it to the assets, suppliers, and activities that touch it.

Go to Privacy > Data Dictionary to get started.


Why a dictionary alongside your RoPA

A RoPA records activities (“we process employee payroll”); the dictionary records data types (“we hold employee salary data”). These are complementary, not redundant:

  • A single data type can span multiple processing activities. Maintaining it once in the dictionary and linking it prevents inconsistency.
  • Regulators increasingly expect a data-type inventory as a standalone artefact, separate from the activity register.
  • The dictionary drives three other privacy workflows in autociso: DSAR readiness enrichment, cockpit risk cards, and DPIA obligation detection.

Getting started: build your inventory

The recommended order is seed first, then customize, then add custom entries as you discover gaps.

1. Seed default GDPR examples

If your dictionary is empty, click Seed default GDPR examples from the list view. This creates 11 pre-configured entries covering the most common GDPR data types:

EntryDefault sensitivity
Email addressMedium
Employee nameLow
Employee salaryMedium
Employee bank accountHigh
Customer billing addressLow
Customer phoneLow
Customer payment dataHigh
Passport numberHigh
IP addressLow
Health dataHigh
Emergency contactMedium

Each seeded entry has a review date set 12 months from the day you seed it. The seed is a one-time action — once your dictionary contains any active entry, the button is disabled and returns an error if triggered again. Only Owners can seed defaults.

After seeding, review each entry and link it to the relevant assets, suppliers, and processing activities in your RoPA.

2. Customize seeded entries

Open any entry from the list and use the Edit action to update the name. Use the Assets, Suppliers, and Activities tabs in the detail view to add links to existing records — no metadata is duplicated, the links simply reference what you have already entered elsewhere in autociso.

3. Add custom entries

For data types not covered by the defaults, create new entries directly from the list view. Required fields are name, data category, and sensitivity level.


Sensitivity levels

Every entry carries a sensitivity level. This is your organization’s operational rating for that data type:

LevelMeaningExample
LowPublicly available or pseudonymousJob title, IP address
MediumDirectly identifying dataEmail address, phone number
HighFinancial or professional dataSalary, bank account, payment data
CriticalGDPR Article 9 special-category dataHealth data, biometric data, racial or ethnic origin

Sensitivity vs. special-category data

These are two separate signals, and both matter:

Sensitivity is your operational label — it drives internal access decisions and cockpit alerts.

Special-category status is a regulatory designation under GDPR Article 9. autociso derives this automatically from the data category you select when creating an entry. You cannot override it manually.

The difference matters operationally: an entry can be High sensitivity without being special-category (for example, bank account details), or it can be Critical and special-category simultaneously (for example, health data). Special-category entries with no completed DPIA are surfaced in the “Sensitive without DPIA” cockpit card (see below) because a DPIA is likely mandatory under Article 35.


Review cadence

Each dictionary entry has a Next review date (defaulting to 12 months from creation). Overdue entries are highlighted in the list view.

To reset the clock on an entry, open the detail view and click Mark reviewed. This records the reviewer, sets last reviewed date to today, and advances the next review date 12 months forward. Managers and Owners can mark entries as reviewed.

The “Dictionary overdue review” cockpit card counts how many entries have passed their review date.


DPIA status

autociso derives each entry’s DPIA status from two inputs: whether the linked data category is special-category, and the DPIA completion status of the linked processing activities. You will see one of:

  • Not required — not special-category data and no linked activities require a DPIA
  • Required – missing — a DPIA is indicated but none has been started
  • Required – in progress — a DPIA is underway for at least one linked activity
  • Completed — all linked active activities have a completed DPIA
  • Mixed — different linked activities are at different stages

You can filter the list by DPIA status to find gaps quickly.


Exports

Two export formats are available from the list view to Managers and Owners.

Export CSV — streams the full filtered dictionary as a comma-separated file. Use this for spreadsheet analysis, sharing with counsel, or feeding into a data mapping tool. The export respects whatever filters are currently active, so you can export just your high-sensitivity entries or just your unmapped ones.

Export PDF — generates a formatted evidence pack via the same rendering pipeline used for other autociso audit reports. Entries are grouped by data category and ordered by sensitivity (highest first). The PDF includes a generation timestamp, your organization name, and per-group entry counts. Use this for regulatory submissions and external audits.

Both exports are unavailable until your dictionary contains at least one entry.


DSAR readiness integration

When you run a DSAR Readiness Check under Privacy > DSAR, the result set now includes a Data types involved column for each matched asset, supplier, or employee record. The chips in that column show which dictionary entries are linked to that system — giving you an instant answer to “what data about this person does this system hold?” without opening each system’s record individually.

The subject identifier you enter for a DSAR check is never stored. Only a cryptographic hash appears in the audit trail.


Privacy Cockpit cards

Three cards on the Privacy Cockpit link directly to filtered dictionary views:

Unmapped personal data — entries with no linked assets, suppliers, or processing activities. An unmapped entry means you know the data type exists but have not recorded where it lives. Click the card to see the list and start adding links.

Sensitive without DPIA — entries rated High or Critical, or flagged as special-category, that have no completed DPIA. These represent your highest-priority compliance gap. Click through to see the affected entries and navigate to DPIA Lite to address them.

Dictionary overdue review — entries whose next review date has passed. Click through, open each entry, and click Mark reviewed once you have confirmed the data type details are still accurate.


Roles and permissions

ActionMemberManagerOwner
View list and detailyesyesyes
Export CSV or PDFyesyes
Create or edit entriesyesyes
Mark reviewedyesyes
Archive or unarchiveyes
Seed default GDPR examplesyes

  • Privacy Cockpit — the three dictionary cards are part of the overall privacy posture score
  • Privacy Register (RoPA) — link dictionary entries to processing activities to keep both layers consistent
  • DPIA Lite — start a DPIA from a processing activity linked to a High or Critical entry
Last reviewed: 2026-05-26

Was this page helpful?

Esc