THE SHORT ANSWER

A first data inventory should describe your records, identify who can answer questions about them, and expose the reasons a proposed use might fail. Start with system metadata and staff interviews. Keep customer records in their existing systems until the purpose, permissions, and review process are clear.

For Owners and operations leaders at established service businesses

What you’ll leave with

  • Make one row per coherent record collection, rather than one row per software subscription.
  • Record uncertainty explicitly. An estimate, a verified count, and an unanswered question are different things.
  • Finish with a decision and a named next action for each collection. A large spreadsheet alone is not a useful result.

1. Give the inventory a question to answer#

Choose a narrow purpose: “Can our closed maintenance jobs support a discussion about diagnosing equipment faults?” is workable. “Find everything valuable in the company” gives your team no stopping point. Write the purpose at the top of the worksheet, along with the business owner who can authorize further work.

For a first pass, ask your operations lead to spend two working hours assembling a draft, with short follow-ups for system owners. This is a proposed timebox, not a completion guarantee. Cover three to five plausible collections; record unresolved questions instead of starting an open-ended cleanup project.

Use existing reports, field lists, retention settings, and interviews. Do not request customer exports or upload screenshots to an outside tool. The FTC recommends understanding where personal information sits and how it moves through a business; that is a sensible foundation before considering a new use. FTC business data security guide.

2. Describe a collection someone can actually assess#

“CRM” is too broad. It might contain prospect contact lists, signed proposals, account notes, and closed service cases, with different origins and restrictions. Give each collection its own row when the record purpose, access rules, or review owner differs.

  • Useful row: closed compressor service jobs from one branch, 2022–2025, with fault codes and technician resolution notes.
  • Separate row: client-provided equipment drawings attached to those jobs.
  • Separate row: employee timesheets used to bill the work.

Distinguish the employee who understands the records from the administrator who can retrieve them and the person who approves a new use. A technician may explain a fault code. An IT manager can describe an export. Neither answer establishes permission to license the material.

3. Capture the fields that change the decision#

The minimum useful record for each collection. Keep passwords, customer names, and raw case notes out of this worksheet.
Field groupWhat to recordWhy it matters
Identity and accountabilityCollection ID, plain description, business owner, administrator, proposed-use approver.Makes follow-up and sign-off possible.
Location and coverageSystem, date range, branches or teams covered, approximate count, count method.Separates a bounded collection from a vague archive.
Structure and outcomeFile types, key fields, links between records, resolution or outcome field.Shows whether someone can follow a complete piece of work.
Known gapsMissing periods, duplicate records, overwritten fields, changing codes, migrated systems.Prevents a misleading description of consistency.
People and confidentialityCategories of personal information, confidential client content, likely sensitive attachments.Identifies what requires closer review.
Origin and restrictionsWho created or supplied it; contract and policy references; unresolved permission questions.Separates possession from authority to authorize a new use.
Retention and next actionRetention-policy reference, hold status to confirm, proposed gate, action owner, review date.Keeps the inventory connected to a decision.

Download the data inventory worksheet. The example is fictional and should be replaced. For a sensitive collection, record “client identifiers present” rather than copying identifiers into the sheet. Store contract references as internal document locations; do not paste confidential terms into a version you plan to share.

4. Work one collection through the questions#

The service manager knows that “closed” sometimes means invoiced or canceled. The first follow-up is therefore to confirm which status and fields distinguish a completed repair from administrative closure. No export is needed to discover that the headline count is too broad.

The administrator reports that equipment model numbers became mandatory only in 2024. Older jobs may need separate treatment. The account lead identifies customer-specific service agreements. The review decision becomes: scope 2024–2025 completed repairs, confirm permission by contract group, and assess attachments separately.

The owner assigns three tasks: the service manager confirms status definitions; the administrator checks available field-level counts; the contract owner locates the relevant agreements. Each gets a review date. The team has a narrower, testable question without sending thousands of client records to anyone.

5. Use three decisions instead of a value score#

  • Advance to a defined review: the collection and proposed use are specific, responsible people are identified, and the next permission or quality check is bounded. This does not approve sharing.
  • Resolve one blocker: a missing agreement, unclear record definition, or access issue prevents a useful next decision. Assign that question to one owner.
  • Set aside for this purpose: the proposed use depends on unavailable outcomes, inseparable restricted material, or work the business has decided not to fund. Record the reason.

Avoid adding these judgments into a single readiness percentage. A strong record count cannot compensate for an unresolved permission question. Likewise, a small, consistent collection with clear boundaries can be easier to evaluate than a much larger mixed archive. Neither observation predicts demand or price.

6. Prepare a description that does not disclose the records#

If an outside discussion is justified, make a separate short description: the business process, approximate date range, types of records, how outcomes are recorded, known limitations, and which permissions remain unresolved. Review even these details for commercial sensitivity. Leave customer identities, system access, and document contents out.

Ask the recipient to explain the intended use, required fields, acceptance criteria, and requested access before preparing a sample. A request for “everything you have” is not a workable specification. Use the offer evaluation guide to turn an inquiry into questions your team can answer.

7. Close the loop after the first review#

End the review with three lists: collections worth a defined next check, unanswered questions with owners, and collections set aside. Save the decision date and supporting references. Update a row when a system migration, contract change, or new proposed use affects it; an old approval should not silently travel to a different purpose.

If the next step requires inspecting actual records, agree the scope, reviewer, access method, and handling requirements first. The inventory has done its job when the owner can authorize that specific task, defer it, or stop it with a documented reason.

Questions owners ask

Do I need a data warehouse to start a business data inventory?

No. Start with a spreadsheet and people who understand the work. Record system names, field descriptions, coverage, and open questions. Build or buy infrastructure only after a defined next step requires it.

How should I estimate volume without exporting customer data?

Ask an authorized administrator for existing dashboard counts or an aggregate report inside the source system. Label the date, filters, and method. If no reliable count is available, write “unknown”; do not turn a staff estimate into a verified number.

Does completing the inventory mean we can license the records?

No. It establishes scope and identifies questions. Any proposed licensing still needs a specific purpose, a review of relevant rights and restrictions, appropriate handling, and agreed commercial terms.

Sources & scope

This guide combines original planning tools with the primary references below. Examples are illustrative. Source material was checked on October 4, 2026; agreements and legal obligations need review for your circumstances.

  1. FTC: Protecting Personal Information — A Guide for BusinessPrimary guidance on identifying personal information, mapping its movement, and managing access and retention. The worksheet and worked example are Data Specialists editorial frameworks, not an FTC checklist.

YOUR NEXT STEP

Start with what you know.

The readiness check asks about your records, access and permissions. Your files stay with you.

Check your data →