hermes

Map personal data processing

Drafts a record of personal-data processing activities from business processes, listing purposes, data categories, recipients, transfers, retention and open questions for privacy review.

context

You help a small organisation build its first data map: a record, process by process, of what personal data it handles, why, where it goes and how long it stays. Under the GDPR this is the record of processing activities; under other laws it is the inventory behind privacy notices, access requests and vendor contracts. It is the foundation for nearly every other privacy task, and its value depends on being accurate rather than complete-looking, so unknowns must be visible, not papered over.

Primary regulation:

task

Business processes:

processes

  1. Split the description into distinct processing activities (one purpose each). A single tool can support several activities; a single activity can use several tools.
  2. For each activity record: purpose; data subjects (customers, users, employees, candidates, suppliers' staff); data categories, flagging special or sensitive categories (health, biometrics, children's data, precise location, financial account data, government IDs); source; systems and vendors; recipients; international transfers; retention period; and security notes if given.
  3. For the regulation, add the fields it typically expects. For gdpr: the organisation's role (controller or processor), and a candidate lawful basis marked "to confirm". For ccpa: whether data may be "sold" or "shared" for cross-context advertising, marked "to confirm". For lgpd: candidate legal basis marked "to confirm". For other: the general fields and a note on what to check.
  4. List vendors with their role (likely processor or service provider vs independent controller or third party), location, and whether a data processing agreement is known to exist.
  5. Flag higher-risk processing that may need extra steps (an impact assessment, consent, opt-outs): large-scale monitoring, profiling with significant effects, sensitive data, children, new technology, employee monitoring.
  6. List gaps: every field you could not fill from the description, as specific questions to the process owner.
constraints
  • You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
  • Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
  • Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
  • When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
  • If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
  • Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
  • This is a working draft for review by the organisation's privacy lead, data protection officer or counsel. Label lawful bases, roles and legal conclusions "to confirm"; never state that processing is lawful or compliant.
  • Use only what the description says. Write "unknown" rather than guessing retention periods, vendor locations or data fields, and turn each unknown into a question.
  • Do not invent article numbers or legal citations. Refer to requirements in general terms unless you are certain of the reference.
  • Keep one row per activity; do not merge different purposes into one row just because they use the same tool.
  • If the description includes actual personal data (names, emails, customer records), do not repeat it; describe categories only.
  • Separate what you verified from what you inferred. Mark inferences as such.
  • When you do not know, say "I don't know" once and state what would settle it.
output format

Scope and assumptions

Bullets: organisation role assumed, regulation, what was in and out of scope.

Processing register

Table: # | activity | purpose | data subjects | data categories (sensitive marked) | source | systems and vendors | recipients | transfers | retention | basis or legal ground (to confirm).

Vendors and transfers

Table: vendor | what it does | likely role | location | agreement in place.

Higher-risk processing

Bullets: activity - why it is higher risk - step to consider.

Gaps and questions

Numbered questions, grouped by process owner.

Next steps

Short checklist.

1 required value still a placeholder; the assistant will ask for it.

details

kind
Prompt: a task you run by name to get one finished thing back
domain
Legal and admin
category
Compliance
level
Intermediate
made for
Founder / business owner, Operations, Legal professional, Product manager
risk
read-only
version
v1.0.0 · incubating
reviewed
2026-10-02
works in
Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Antigravity, OpenCode, Windsurf, Zed, Continue, AGENTS.md, ChatGPT, claude.ai

Edit on GitHubReport a problem

use in

Hodios CLI
npx @hermes-hq/hodios install map-personal-data-processing --target claude-code
Agent Skills
npx skills add hermes-hq/hodios-dist --skill map-personal-data-processing -a claude-code
Add the Hodios marketplace (once)
claude plugin marketplace add hermes-hq/hodios-dist
Install the legal-admin plugin
claude plugin install hodios-legal-admin@hodios

The plugin brings every entry in this domain at once.

pairs well with

All of Compliance
PromptCompliance

Build a compliance readiness checklist

Builds a readiness checklist for a named regulation or framework applied to a specific business, covering applicability, evidence, owners, priorities and points to verify with counsel.

build-compliance-checklist
PromptPolicies and terms

Write a privacy policy

Drafts a plain-language privacy policy strictly from a product's actual data practices, structured for the stated jurisdictions, and flags every gap or risky practice for legal review.

write-privacy-policy
PromptCompliance

Assess EU AI Act obligations

Maps an AI system to the EU AI Act's risk categories and roles such as provider or deployer, and lists the likely obligations and application dates to verify with counsel.

assess-ai-act-obligations
PromptCompliance

Audit a website's privacy compliance

Checks a website's cookie banner, consent, privacy notice, forms and trackers against common privacy-law expectations and lists prioritised fixes to confirm with a privacy professional.

audit-website-privacy-compliance
PromptCompliance

Check email and SMS marketing compliance

Checks an email or SMS marketing programme against consent and content rules such as GDPR, ePrivacy, CAN-SPAM and CASL for each market, and lists concrete fixes ranked by risk.

check-email-marketing-compliance
PersonaCompliance

Compliance officer

Acts as a pragmatic compliance officer for small organisations who reads obligations closely, turns them into proportionate controls with evidence, and escalates interpretation to counsel.

compliance-officer