Reviewed · Hosmio resources
Before you start
Bring a basic architecture sketch, the people responsible for the application and backups, and any client restrictions. Use categories and synthetic examples. Do not put actual client records, passwords, access tokens or unredacted logs into the worksheet.
01
Follow one complete user task.
Choose a representative task such as uploading a project document to a client portal. Trace where the request goes, where its metadata is stored, where the file ends up and what happens after upload. Include thumbnails, queued processing, outbound notifications and error reporting when they exist. The goal is to describe your implementation, not to fill every possible category.
Then trace a second task that reads or exports data. Exports often reveal copies absent from an infrastructure diagram: an operator’s downloaded archive, a reporting integration or a file attached to a support request. Ask who controls each destination and why it is needed.
02
Separate persistent copies from access.
| Record | Purpose / responsible role | Evidence still needed |
|---|---|---|
| Application database | Project metadata / application operator | Actual host country and retention rule |
| Uploaded documents | Client files / content owner | Storage destination and deletion process |
| Recovery copy | Rebuild service / recovery operator | Backup location, access and restore result |
| Error reporting | Investigate failures / incident owner | Fields exported and receiving organization |
| Administrative session | Maintain application / authorized operator | Access arrangement and audit process |
An access row is useful even when it does not create an intentionally retained copy. Record the organization and process involved, what the person can see, and whether an export can occur. Do not make a universal legal conclusion from that row. The EDPB’s transfer criteria depend on the actual organizations and processing context. EDPB: international data transfers ↗
03
Label the quality of each answer.
Use a small set of states: documented, stated but not checked, unknown, and not applicable with a reason. Attach the source and review date to the answer, not just to the page containing the table. A diagram drawn by your own team and a contract supplied by a provider answer different kinds of questions.
For example, your code may establish that an error report excludes document contents, while only the reporting supplier can state where its storage or support process operates. Keep those pieces of evidence separate. When they disagree, raise a specific question and retain the unresolved state until the conflict is addressed.
04
Give every copy an owner and an end condition.
For each persistent copy, record why it exists, how long the project needs it, who controls deletion and what happens when the service ends. A recovery copy can be necessary while still needing a defined retention process. “Backed up” is not a complete answer to whether old data can be removed or how long it remains recoverable.
Check routine exports too. If an operator downloads an archive to investigate a problem, the team should know where it is held and when it is removed. Refer to protected evidence rather than embedding the archive in the map. The record itself should remain useful without exposing the data it describes.
05
Resolve an incomplete portal map.
In an illustrative review, the application operator can explain production storage and scheduled exports, but the backup destination is listed simply as “provider backup”. The recovery operator asks for the destination scope, access rules and an actual restore procedure. Until those are supplied, the row stays unknown and the country decision remains conditional.
Meanwhile, an error-reporting integration is found to include full request URLs. The team reviews whether those URLs can carry project identifiers, updates its field inventory and asks the client contact to assess the changed data flow. No country or compliance outcome is inferred from this example; it shows how the map can expose a concrete unanswered question.
06
Check completeness and maintain the map.
Have the backup operator and the application maintainer independently walk through a restore and an incident investigation. Ask where each step obtains data and who can access it. If either process uses a destination missing from the worksheet, add it and assign an owner for the remaining facts.
A usable map ends with a short open-items list, each tied to a responsible role and a decision it affects. Review it after adding integrations, changing backup policy, granting a new administrative route or moving regions. Use the hosting decision matrix to evaluate the resulting facts and the change-approval guide when the arrangement changes.
This worksheet organizes operational evidence for the project’s advisers. It does not establish applicable law, authorize a transfer or certify data residency. The selected server country does not establish the location of backups, exported data or administrative access.