Many organisations know which programs they use but not exactly where the data is. Email, cloud folders, a NAS, phones, bookkeeping, a website, CRM, backups and exports can all contain different copies.
A useful inventory is therefore not a list of brand names, but a map of data, locations, accounts, access rights, recovery routes and retention periods.
Start with each work process: what information comes in, where is it stored, who uses it, where is a copy made and how is it deleted? Also record physical devices and exports on USB media or local drives.
Work from concrete towards complete. A simple table that is correct is more useful than an extensive register based mainly on assumptions.
Because access to data is often controlled by accounts that exist outside the primary system. A cloud account may be recovered through a private email address; a domain through an old telephone number; a NAS through a local administrator. Those routes are part of security.
Read the current terms, privacy information and processing agreements and compare them with the intended use. A procedure can be described neatly and still create a technical or privacy risk if the chosen service receives broader rights than expected.
Within Digital, such an inventory can be built together using real systems and accounts. For everyday skills around accounts, files and recovery, the digital self-reliance workshop is also relevant.