Dabish Digital
Security

Five mistakes teams make with data privacy

The version of this that works is simpler than the version most people imagine. These are the ones we run into repeatedly when we audit data privacy.

The realistic threat for most small businesses is automated and opportunistic, not targeted. If it only works because one person remembers to do something, it does not work yet.

Where it usually goes wrong

  • Treating it as a launch task rather than an ongoing one
  • Assuming someone else already owns it
  • Collect only what you can justify keeping
  • Deletion policies matter as much as collection ones
  • Never checking whether the fix actually worked

Know where personal data actually lives. Getting it slightly wrong is survivable. Ignoring it entirely is not. If it only works because one person remembers to do something, it does not work yet.

What to do next

In practice

Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about data privacy before you move on:

  • Someone can say what the current setup is without going to look
  • Know where personal data actually lives — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

Pick the one that would hurt most if it failed, and start there.