DI Management
What Is DI?
A data inventory (DI) is a personal data record that catalogs the data source, type, storage location, shared parties, and retention period, providing a comprehensive view of personal data transfers.
Creating a DI
A DI needs to be created each time an application is added. One DI corresponds to one S code.
- Log in to the PCMC.
- In the navigation pane, choose DI Management.
- Click Create DI in the upper left corner. The Create dialog box is displayed.
- Configure Business Information based on Table 1.
Table 1 Business information parameters Parameter
Description
S Code
Enter a complete S code, for example, S10004, to search for the corresponding application. If an application owner is responsible for multiple S codes, a DI must be entered for each S code.
Country
Select the country/region where the management organization is registered.
Legal Entity
Enter a keyword for fuzzy search to find the legal entity that the application belongs to. It will be used for compliance records.
Usage Scope
Set the user group of the application. If the application is not limited to internal use, a privacy statement to-do task will be generated.
Description
Briefly describe the application.
Whether to collect personal information
Set whether the application collects personal data from external systems. Receiving personal data from other applications is also considered as collecting personal data.
- Click Next. On the Processing Purpose page, click Add Processing Purpose and configure parameters based on Table 2. You can add multiple purposes.
Table 2 Processing purpose parameters Parameter
Description
Processing Purpose
Select the purpose for collecting and using personal data.
Personal Data Type
Click to check all the personal data items bound to the S code. Select specific personal information, including names, phone numbers, and birth dates.
Data Subject Location
Location where a user receives a product or service. One or more countries/regions can be selected.
Data Processing Role
- Joint Controller: Multiple joint controllers determine the purposes and methods of data processing together.
If you select this role, you also need to configure Name of the Joint Controller Entity.
- Subprocessor: It is a downstream service provider delegated by the processor to perform specific processing tasks.
If you select this role, you also need to configure Data Processor Name and Data Processor Contact Information.
- Controller: It determines one or more purposes or methods of personal data processing and is responsible for the processing.
- Processor: It acts on behalf of the controller, processing data strictly according to their instructions and lacks the authority to make independent processing decisions.
When selecting this role, you also need to configure Name of the Data Controller Entity.
- Other: Other roles have access to data but have no authority to make independent processing decisions.
Data Subject Type
It refers to the type of a data subject identity, such as a user, employee, or supplier.
Data Subject Quantity
Estimated number of people whose data will be collected for processing.
Personal Data Collection
- Collection Type:
- Direct Data Subject Collection: Data is directly obtained from the source.
- Non-Direct Data Subject Collection: Data is obtained from suppliers or third parties.
- Collection Method:
- If Direct Data Subject Collection is selected, you need to configure Collection Method, for example, System-Automated Collection or User Input.
- If Non-Direct Data Subject Collection is selected, you need to configure Source when not collected directly from the data subject.
- Storage/Access Location:
Country/Region where personal data is stored. Generally, its value is the country/region where the system and database servers are located. If certain assets are stored in multiple regions due to architecture design, enter all the storage locations.
Personal Data Usage and Retention
- Whether to use automated decision-making:
Automated decision-making is the process of automatically making decisions without any human intervention. For example, automatic video recommendation.
- Whether used for user profiling:
User profiling involves the automated processing of personal data to evaluate and predict personal preferences, behaviors, interests, and habits. For example, it can analyze the types of videos that a user likes.
- Retention Period:
Select a retention period based on the actual conditions of the application.
- Deletion Method:
It specifies how personal data is destroyed after its retention period expires. For example, manual or automatic data deletion.
Personal Data Disclosure
Whether to disclose personal data to third parties (external):
- If you select Yes, configure the following parameters:
- Disclosure Type (Optional)
- C2P (Controller To Processor)
- C2C (Controller To Controller)
- P2C (Processor To Controller)
- P2P (Processor To Processor)
- Recipient Type: Type of the legal entities that share data, including suppliers, partners, and subsidiaries.
- Recipient Entity Name (Optional): Name of the legal entity that receives data.
- Recipient Transmission Method: How the recipient transmits data, for example, through email or remote access.
- Disclosure Type (Optional)
- If you select No, go to the next step.
Cross-border Transfer
Whether it involves cross-border transfer of personal data: It specifies whether personal data is transferred between jurisdictions. Many regions, most notably the EU, impose stringent restrictions on such transfers.
- If you select Yes, configure the following parameters:
- Cross-border Data Receiving Country: Country/Region that receives personal data.
- Cross-border Transfer Method: Mode of cross-border transfer, such as application programming interface (API), remote access, and device.
- Cross-border Transfer Mechanism: Cross-border transfer of personal data can be allowed only if the country/region where the data recipient is located meets certain security assurance requirements. For example, the GDPR governs cross-border data transfers through SCCs and adequacy decisions.
- If you select No, go to the next step.
- Joint Controller: Multiple joint controllers determine the purposes and methods of data processing together.
- Click Next Step. The Configuration List Confirmation page is displayed. Check whether the content is correct. If it is, click Submit Audit.
Approval Process
A DI record must be submitted for the following approval process. You can check it in Personal Center.

Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot