Dabish Digital
Security

Data privacy: the questions we get asked most

It comes up on almost every project, usually later than it should. The questions about data privacy that come up most often on our calls.

The realistic threat for most small businesses is automated and opportunistic, not targeted. Doing this properly once is usually cheaper than doing it approximately three times.

Do we need to care about this?

Collect only what you can justify keeping. The cost of getting this wrong is rarely visible on the day it happens. Anything you cannot measure here, you are deciding by taste, which is fine as long as everyone knows it.

Can it wait until after launch?

Occasionally. More often the post-launch version costs several times the pre-launch one. It is worth being explicit about, because assumptions differ quietly.

How do we know it is working?

Know where personal data actually lives. The reasoning matters more than the rule, because the rule has exceptions. If it only works because one person remembers to do something, it does not work yet.

How to tell if yours is fine

The cheapest security work is the boring kind done on a schedule. Three things worth confirming about data privacy before you move on:

  • Someone can say what the current setup is without going to look
  • Collect only what you can justify keeping — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

The point is not perfection, it is knowing which of these you have consciously chosen to skip.