Sysdoc's four-stream approach starts by looking at data. When considering data, organisations should remember that 70-80% of all personal data normally lies outside a main enterprise system. This so-called “unstructured data” is well within the scope of GDPR.