Privacy & Compliance
-
You Cannot Fulfil a Deletion Request Without a Data Map
Deleting a user requires knowing every system holding their data, including backups, logs, warehouses and third-party processors nobody documented.
Read More » -
Privacy by Design Means Deciding What Not to Collect
Retrofitting privacy controls onto a system that already collects everything is far harder than deciding at the outset what genuinely…
Read More » -
Passing an Audit and Being Secure Are Different Achievements
A framework certifies that documented controls operated as described. It does not certify that those controls would stop an attacker.
Read More » -
Personal Data Ends Up in Logs Because Logging Is Convenient
Nobody decides to log a national ID number. Someone logs a whole request object during debugging and the line survives…
Read More » -
You Have 72 Hours: Breach Notification Readiness Before You Need It
Notification deadlines start when you become aware, not when you finish investigating. Most organisations cannot determine what was accessed fast…
Read More » -
Where Your Data Physically Sits Is a Legal Question, Not a Technical One
Choosing a cloud region for latency reasons can silently create a legal transfer obligation nobody on the engineering team was…
Read More » -
Privacy Engineering Starts With Deleting Things
Most privacy programmes write policies about data they cannot locate and promise deletion they cannot perform. The engineering work is…
Read More » -
Vendor Questionnaires Measure Documentation, Not Security
A two-hundred-question spreadsheet answered by a sales engineer tells you the vendor has policies. It says almost nothing about your…
Read More »