Can you identify what PII you have, in production, backup systems, on-premises and across clouds?
Can you prove that you can identify personal information?
Where is it stored? Should it be there?
Is it protected?
Who owns it and who has access to the data?
Should you retain it or defensibly delete it?
Are you able to identify redundant data so you can reduce infrastructure/storage costs?
Are you compliant with the Protection of Personal Information Act (POPIA)?