For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.
What you will achieve
Maintain reusable descriptions of the data your organisation uses and the categories of people it relates to, then link them to processing activities.
A data-subject record here describes a category such as employees or applicants. It is not an instruction to upload a list of named individuals.
Before you start
Agree the terminology with process and privacy owners. Check existing records before creating another “Customer data” or “Employees” entry. Know which processing activities should use the record.
Create or maintain a data entity
- Open the data-entity catalogue and choose its create action.
- In Create New Data Entity, enter a specific name and description. Explain what the dataset contains and its boundary.
- Choose the category, data type and classification shown in the form.
- Select the appropriate Data Owner, then Create Data Entity.
- Open the saved entity. Maintain its schema and relationships through the relevant tabs, including the systems and processing activities that use it.
- Review compliance and retention information with the owner. Distinguish a stated retention requirement from evidence that deletion is actually performed.
For an existing entity, update the record deliberately and inspect connected activities before changing its meaning.
Create or maintain a data-subject category
- Open the data-subject catalogue and select its create action.
- In Create Data Subject, enter a clear name, select the category and explain who is included or excluded.
- Save, then inspect Data Entities, ROPAs and other linked records.
- Review Rights defaults with the authorised privacy owner. These defaults can inform linked processing records; do not treat them as a universal legal conclusion.
- Reopen a representative linked RoPA to check whether the intended defaults and any activity-specific overrides are understood.
Check it worked
Follow one processing activity to its data entity and data-subject category, then back again. Confirm the names, scope, classification and links agree. Use the available audit/review surfaces to inspect the recorded change.
If something goes wrong
| Problem | Next action |
|---|---|
| Two records appear to describe the same thing | Compare scope and downstream links before asking for consolidation |
| Classification is unclear | Ask the data owner; do not use the least restrictive option for convenience |
| A downstream RoPA does not match | Inspect its explicit links and overrides |
| A record is no longer used | Review dependencies and retention before deletion; preserve required history |
Human judgement matters
Descriptions should explain categories without copying live personal data. A reusable default is a starting point for contextual review, not a substitute for it.
What next?
For the wider context, see Manage privacy records and assessments.
Update the affected RoPAs and assessments, and schedule a review with the data owner when the underlying dataset or population changes.
Get help
Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.