The DSAR That Takes Fifteen Minutes
Why a single subject access request can consume a week of engineering time — and what changes structurally when personal data stops being scattered.
BLOG
Notes on personal data and what the law actually requires of a database.
Why a single subject access request can consume a week of engineering time — and what changes structurally when personal data stops being scattered.
"The database is encrypted" answers a question almost nobody is asking. What encryption at rest actually defends against — and the four ways data leaks around it.
Nobody decides to build a PII vault. Every company running for a few years has one anyway — scattered across services, maintained by payroll, invisible on the roadmap.
Immutable backups defeat selective deletion by design. What the ICO's "beyond use" standard requires in practice, and what crypto-shredding does and doesn't solve.
Your admin panel has a delete button. Your privacy policy references it. When a user invokes GDPR Article 17 — it doesn't do what you think it does.
There is a clause in your cloud provider agreement. You clicked Accept. Here is what it actually says.
Your security admin left on Friday. A major client calls Monday morning about a potential breach. You have no answers. What's your plan for that Monday morning?