Data Inventory
Identify and maintain an inventory of all digital personal data processed across your systems, to support data accuracy, purpose limitation, and retention management.
Data Inventory helps you build and maintain a live record of the personal data your organization processes. You connect the systems that hold data, scan them to find what personal data is actually there, review what the scan proposes, and shape the result into the entities that make up your inventory: systems, collection sources, data subjects, processing activities, and vendors. That inventory is what your RoPA and DPDPA Purpose Registry reports are generated from. The module's menu has Dashboard, Inventory (with tabs for Data Systems, Data Collection Sources, Data Subjects, Processing Activities, and Vendors), Data Flow, Configuration (Scanner, Integrations), and Reports (RoPA Reports, DPDPA Purpose Registry), plus Metadata Definitions.
The building blocks
Integration. A connection to a source of personal data: a database or a storage location. Registering an integration also creates the data system that represents it in your inventory. Manage integrations under Configuration > Integrations. See Integrations.
Scan. A run over an integration's tables, collections, or objects that reads the data and looks for personal information. A scan produces findings: the resource it looked at, what it detected, and a confidence score.
Data object and category. Every detected data type is mapped to a data object inside a category (for example an identifier, a financial detail, or a health record). Each data object carries a mapping to GDPR, DPDPA, and CCPA/CPRA concepts and a risk score, so a finding is never just "this looks like an email address": it is tied to a defined category with a known regulatory weight.
Data point classification. The proposed classification for one discovered column, field, or object path. It starts out needing review; you approve or reject it, with a note, from the data system's Data Points tab.
Data system. One source in your inventory, either created automatically from an integration or added manually when there is nothing to scan.
Data Collection Sources, Data Subjects, Processing Activities, Vendors. The remaining inventory entities under Inventory. Collection sources are the channels through which you collect personal data. Data subjects are categories of individuals. Processing activities describe the purposes and operations you perform, linked to the systems, sources, subjects, and vendors involved. Vendors are the third parties you share data with or receive services from.
Data Sharing. A link recorded under Data Flow between a source system and a destination system, optionally mapping individual data points between them, so you can see where data moves and whether it crosses borders.
Metadata Definitions. Custom attributes you define once, each with a key, label, and value type, that then attach to inventory records and data sharing links. Your RoPA and DPDPA reports read processing activity attributes, so these need to be filled in before you generate a report.
RoPA Reports and DPDPA Purpose Registry. Reports generated from a processing activity and everything linked to it: the systems, subjects, sources, vendors, and attributes attached to it.
How it fits together
Connect
Register an integration for a database or storage source under Configuration > Integrations. Neostra tests the connection and, once it succeeds, creates the corresponding data system and queues an initial scan.
Scope
Optionally limit what a scan touches: include or exclude specific tables, collections, or columns so a scan only covers what you intend.
Scan
Run a scan on demand or on a schedule. Neostra reads the source's data and records findings: what was detected, where, and with what confidence.
Review
Open the data system's Data Points tab and work through the proposed classifications. Approve or reject each one, with a note.
Model
Shape approved findings and manual entries into your inventory: data systems, collection sources, data subjects, processing activities, vendors, and the data sharing links between systems.
Report
Generate RoPA reports and the DPDPA Purpose Registry from the processing activities in your inventory.
Supported sources
You can register and scan these source types end to end:
| Source | What is scanned |
|---|---|
| PostgreSQL | Column values in each table in the configured schema |
| MySQL | Column values in each table in the configured database |
| MongoDB | Document fields in each collection |
| Amazon S3 | Text-like objects up to a size limit |
| Amazon DynamoDB | Item attributes in each table |
Full setup details, including what to enter for each source and how scan scope and schedules work, are in Integrations.
Protecting scan results
Credentials you enter for an integration are encrypted and shown redacted afterward. For scan findings themselves, you choose how much detail is kept: no retained excerpt, a redacted excerpt with surrounding context, or a hashed value for counting duplicates without storing them. See Integrations for the retention options and how to set them before your first scan.
Who does what
| Role | Typical tasks |
|---|---|
| Privacy admin or DPO | Registers integrations, defines metadata definitions, models processing activities and vendors, generates reports. |
| Data or IT owner | Reviews and approves or rejects proposed data point classifications for systems they own. |
| Compliance analyst | Maintains data collection sources, data subjects, and data sharing links; keeps processing activity attributes current for reporting. |
How it connects
Assessments. When building an assessment, you can add placeholders for data systems, collection sources, subjects, processing activities, or vendors, and link them to actual inventory objects once the assessment is underway. See Assessments.
Explore the module
Integrations
Register sources, test connections, scope and schedule scans, and set scan evidence retention.Inventory
Data systems, collection sources, data subjects, processing activities, vendors, and data flow.Reports
Generate RoPA reports and the DPDPA Purpose Registry from your processing activities.