How to get data privacy right
This is one of those topics that looks small until it costs you something. The short answer to data privacy is that it is mostly a sequence of small decisions, not one big one.
The cheapest security work is the boring kind done on a schedule. Doing this properly once is usually cheaper than doing it approximately three times.
What is actually at stake
Collect only what you can justify keeping. Small and consistent beats large and occasional here. It is the sort of thing that looks like polish right up until it costs you an enquiry.
The steps
- Establish what you have today before changing anything
- Deletion policies matter as much as collection ones
- Know where personal data actually lives
- Write down the decision so the next person does not re-litigate it
Know where personal data actually lives. The reasoning matters more than the rule, because the rule has exceptions. Write the reasoning down alongside the decision, because the reasoning is what changes first.
Where to go from here
What this looks like day to day
The realistic threat for most small businesses is automated and opportunistic, not targeted. Three things worth confirming about data privacy before you move on:
- Someone can say what the current setup is without going to look
- Know where personal data actually lives — and you know whether that is true here
- There is a way to tell whether the last change to this helped
The point is not perfection, it is knowing which of these you have consciously chosen to skip.