No fluff. Technical depth, compliance context and real-world scenarios.
Why a single subject access request can consume a week of engineering time — and what changes structurally when personal data stops being scattered.
"The database is encrypted" answers a question almost nobody is asking. What encryption at rest actually defends against — and the four ways data leaks around it.
Nobody decides to build a PII vault. Every company running for a few years has one anyway — scattered across services, maintained by payroll, invisible on the roadmap.
Most companies think a delete button satisfies GDPR Art.17. It doesn't. Here's what compliant erasure actually requires technically — WAL, replicas, backups, and all.
Your admin panel has a delete button. Your privacy policy references it. When a user invokes GDPR Article 17 — it doesn't do what you think it does.
There is a clause in your cloud provider agreement. You clicked Accept. Here is what it actually says.
Your security admin left on Friday. A major client calls Monday morning about a potential breach. You have no answers. What's your plan for that Monday morning?