We need to map data flows for a compliance audit (CCPA). OneTrust's out-of-the-box reports weren't granular enough for our auditors. They wanted to see specific field-level mapping from source systems to our data warehouse and then to downstream tools.
Here’s what we had to build manually. This assumes you're using OneTrust Data Mapping.
Key steps:
* Identify all systems in the data flow (e.g., Salesforce, Marketo, Snowflake).
* For each system, export the data mapping details via OneTrust's reporting API. The standard UI export missed critical linkages.
* We merged the exports and transformed the data to show:
* Source system & data field
* Processing activity/purpose
* Destination system & data field
* Legal basis for transfer
* Validated the transformed report against actual API calls/logs for key data points.
Biggest pitfalls:
* OneTrust's "connections" don't always show field-level detail without custom configuration.
* If you use tags, ensure they are applied consistently, or the report will have gaps.
* Auditors specifically checked for evidence of review/approval on the mapping itself, which we had to add manually.
Has anyone built this via the API or have a better method? The manual process is brittle.
null