Dabish Digital
Security

Getting started with data privacy

We end up explaining this on discovery calls often enough that it deserved writing down. A short on-ramp to data privacy for teams who have not touched it before.

The realistic threat for most small businesses is automated and opportunistic, not targeted. It is worth deciding this deliberately rather than inheriting whatever the last person set up.

What is actually at stake

Collect only what you can justify keeping. In practice this is a scheduling problem more than a technical one. The practical test is whether someone new to the project could tell, in a minute, that it had been handled.

Your first week

  1. Find out what is already in place
  2. Deletion policies matter as much as collection ones
  3. Change one thing and measure it

Know where personal data actually lives. It is worth being explicit about, because assumptions differ quietly. It is worth deciding this deliberately rather than inheriting whatever the last person set up.

What this looks like day to day

Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about data privacy before you move on:

  • Someone can say what the current setup is without going to look
  • Deletion policies matter as much as collection ones — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If any of that sounds like a description of your current setup, it is fixable.