GDPR and Data Lineage
How Data Governance Makes Compliance Routine
- AI In Business
Most compliance effort in a mid-sized company goes into finding personal data before anyone can protect it. Data lineage turns that search into a lookup.
Two-thirds of organizations need two weeks or more to answer a single subject rights request, and the average manually processed request costs roughly USD 1,400. Gartner published those numbers in 2020, drawing on its 2019 Security and Risk Survey. Since then, the number of requests has risen, and the number of systems holding personal data has risen with it.
For a company running an ERP, a CRM, a payroll system, a webshop and a handful of Excel exports, the difficulty of the GDPR sits in a single question: where does this person’s data live, and where has it traveled? Everything else in a compliance response follows from the answer.
What the regulation asks you to prove
The GDPR is built on accountability. Article 5(2) makes the controller responsible for demonstrating compliance, and several obligations turn that principle into concrete evidence.
- Article 30 requires a written record of processing activities: purposes, categories of data subjects and personal data, recipients, transfers to third countries, and the envisaged erasure deadlines.
- Article 15 gives the data subject the right to learn which categories of personal data you hold, who receives them, and how long you intend to keep them.
- Article 17 gives the right to erasure, and Article 5(1)(e) limits storage to the period necessary for the purpose.
- Article 19 requires you to communicate every rectification, erasure or restriction to each recipient to whom the personal data have been disclosed.
- Article 12(3) sets the clock at one month from receipt, with an extension of two further months available where the request is complex, or requests are numerous.
Read together, these articles describe a map. A supervisory authority wants to see where personal data enters the company, which systems it passes through, who receives a copy, and when each copy disappears.
Why the map is hard to draw
Most mid-sized companies do hold an Article 30 record. It usually lives in a spreadsheet, was assembled once during a compliance project, and describes the systems as they stood on the day it was written.
The operating reality keeps moving. A marketing colleague exports a customer list to a campaign tool. Finance builds a dashboard on a nightly extract. A developer copies the production database into a test environment. An integration pushes contact records to a partner portal. Every one of these is a legitimate business step, and every one creates a new home for personal data that the spreadsheet has no way of knowing about.
Personal data rarely lives in structured databases alone. Documents and emails create the same visibility and control challenge at a much larger scale. See how organizations can process this information systematically in Intelligent Document Processing (IDP) →
The distance between the documented picture and the operating picture is where compliance risk accumulates. When a request arrives, someone has to close that distance manually, by email, against a deadline.
What data lineage means in business terms
Data lineage is the documented path of a data element from its origin to every place it is used. For something as ordinary as a customer email address, lineage answers four questions.
- Where was it created: which source system, form, or import?
- Which systems, reports, or files copy it, and through which interface or scheduled job?
- Who has access at each stop, including external processors and partners?
- Which retention rule governs its deletion at each stop, and who enforces that rule?
Inside a data governance program, lineage sits alongside the glossary, which defines what each data element means; the ownership model, which names the person accountable for it; and the quality rules, which define what counts as valid. Lineage supplies the geography that the other three assume.
A use case: one erasure request, from arrival to evidence
The walkthrough below is illustrative. It describes a typical mid-sized situation and contains no figures from any specific client engagement.
Without lineage
A former customer asks for erasure. The data protection officer emails IT, finance, marketing, and customer service. Four teams search their own systems. Marketing finds the record in the campaign tool and recalls a list exported to an agency six months earlier, with nobody certain whether the agency still holds it. The reporting team confirms one copy in the warehouse layer and a second in the backup set.
Two weeks go into coordination. The company sends a response confirming erasure, and the file behind that response contains no evidence that every copy was covered. If the authority asks later, the company has an email thread.
With lineage
The same request enters the request log. The lineage view returns every location holding that customer’s data: the CRM record, two integration tables, the reporting layer, the campaign tool, one archive and the backup set, together with the two external recipients that received exports and the retention rule attached to each stop.
Customer service triggers the deletion workflow. Each step is logged. The Article 19 notification goes to both recipients from a list that has been maintained continuously. The response is left within four working days, and the file shows which systems were touched, by whom, and on which date.
The legal obligation was identical in both cases. What changed is the elapsed time and the quality of the evidence at the end.
What the same map is worth beyond compliance
Companies build lineage for the regulator and then discover that four other problems were waiting for the same answer.
- Retention becomes enforceable. Storage limitation is a rule you can apply once you know every location, and a rule you can only hope for while copies stay invisible.
- Vendor management gets a current recipient list. Processor agreements, security reviews and offboarding all draw on the same register.
- Breach response gains speed. The 72-hour notification deadline in Article 33 turns on one early question: which data, in which systems, for how many people?
- AI initiatives inherit a clean starting point. Before any model is trained, the team can state which inputs contain personal data and on what legal basis they may be used.
The pattern shows up in the research as well. In the 2026 State of Data Integrity and AI Readiness study by Precisely and Drexel University’s LeBow College of Business, 71 percent of organizations with a data strategy and a data governance program reported high trust in their data, compared with 50 percent of those without one.
Compliance becomes much easier when trusted information can be found across systems instead of reconstructed manually for every request. We explore that broader challenge in AI Search: Turning Organizational Knowledge into Confident Decisions →
Four steps that fit inside one quarter
Full enterprise lineage is a multi-year program. Useful lineage is far smaller, and a mid-sized company can reach it in a quarter by narrowing the scope.
- Pick one data domain. Customer or employee data, whichever generates more requests. One domain end to end beats every domain halfway.
- Map the real flows. Follow the data from its source to every downstream copy, including manual exports, shared drives, and reports. Ask the people who perform the exports, since the interface documentation rarely mentions them.
- Attach an owner and a retention rule to each stop. A location with no named owner is a location nobody will delete from.
- Rehearse one request end to end. Take a real closed case, run it through the new map, and measure the elapsed time. That number is your compliance readiness, expressed in days.
The one minute test
GDPR compliance in a mid-sized company is a search problem before it becomes a legal problem. The legal text has been stable since 2018. The number of places where customer data lives has changed every year since. Data lineage is the part of data governance that keeps those two facts in the same document.
The test is short. Take your most recent subject request and ask three questions: how many colleagues were pulled in, how many days it took, and how you would prove today that every copy was covered. If assembling that answer takes longer than a minute, the map is the piece that is missing.
Do you know where your personal data lives today?
If your systems have multiplied faster than your documentation, the first useful step is a structured look at the current state. The Data Assessment maps where your data is created, where it is stored, and where the breaks occur in the flow of information.
2 to 3 weeks | 2 to 3 workshops | 8 to 12 page executive summary | from EUR 1,450 + VAT
You receive the 3 to 5 main pain points, the business impact of each, and the order in which they should be addressed. If you proceed within 60 days, 60 to 90 percent of the fee can be credited toward the next phase, depending on scope.
Sources
- European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). Source for Articles 5, 12, 15, 17, 19, 30, and 33. Read article →
- Gartner. (2020, February 25). Gartner Says Over 40% of Privacy Compliance Technology Will Rely on Artificial Intelligence in the Next Three Years. Source of the two-thirds response time figure and the USD 1,400 average cost per manually processed subject rights request. Read article →
- Omnit. (2026). Data Assessment. Source of the engagement length, workshop count, deliverable length, price, and credit terms. Read article →
- Precisely & Drexel University LeBow College of Business. (2026, January 21). State of Data Integrity and AI Readiness. Source of the 71% and 50% data trust figures. Read article →

Lajos Fehér
Lajos Fehér is an IT expert with nearly 30 years of experience in database development, particularly Oracle-based systems, as well as in data migration projects and the design of systems requiring high availability and scalability. In recent years, his work has expanded to include AI-based solutions, with a focus on building systems that deliver measurable business value.
Related posts

A practical guide for CFOs and senior decision-makers at mid-sized companies
Are you sure AI is the right next step?
We help uncover the real opportunities, limitations, and realistic next steps.



