BLOG

Blog

Notes on personal data and what the law actually requires of a database.

30 August 2026

The DSAR That Takes Fifteen Minutes

Why a single subject access request can consume a week of engineering time — and what changes structurally when personal data stops being scattered.

16 August 2026

Encryption at Rest Is Not Protection

"The database is encrypted" answers a question almost nobody is asking. What encryption at rest actually defends against — and the four ways data leaks around it.

2 August 2026

The Accidental PII Vault

Nobody decides to build a PII vault. Every company running for a few years has one anyway — scattered across services, maintained by payroll, invisible on the roadmap.

22 July 2026

Article 17 and the Backups You Cannot Edit

Immutable backups defeat selective deletion by design. What the ICO's "beyond use" standard requires in practice, and what crypto-shredding does and doesn't solve.

6 April 2026

The Delete Button That Doesn't Delete Anything

Your admin panel has a delete button. Your privacy policy references it. When a user invokes GDPR Article 17 — it doesn't do what you think it does.

26 March 2026

Your Cloud Provider Can Read Your Data. You Agreed to It.

There is a clause in your cloud provider agreement. You clicked Accept. Here is what it actually says.

13 March 2026

The Monday Morning That Changes Everything

Your security admin left on Friday. A major client calls Monday morning about a potential breach. You have no answers. What's your plan for that Monday morning?