Dabish Digital
Security

A practical checklist for data privacy

Every audit we run turns up some version of this. Run through this the next time data privacy comes up.

The realistic threat for most small businesses is automated and opportunistic, not targeted. Anything you cannot measure here, you are deciding by taste, which is fine as long as everyone knows it.

The checklist

  • Collect only what you can justify keeping
  • Deletion policies matter as much as collection ones
  • Know where personal data actually lives
  • Someone is named as the owner
  • There is a date to review it again

Why this earns attention

Collect only what you can justify keeping. In practice this is a scheduling problem more than a technical one. The failure mode is not doing it wrong, it is doing it once and assuming it stays done.

The short version

Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about data privacy before you move on:

  • Someone can say what the current setup is without going to look
  • Collect only what you can justify keeping — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If any of that sounds like a description of your current setup, it is fixable.