Privacy & data handling

Know where data goes and when it should leave.

Map collection, access, retention and external processing so requirements can be translated into controls.

Talk to usExplore service
Follow information through its lifecycleExample workflow
Collection

Required fields and a stated purpose

Processing

Approved systems and access boundaries

Retention

Deletion rules and recovery copies

An implementation example

Make data handling an implemented behaviour

Map personal and sensitive information across applications, integrations, logs and backups. Turn agreed requirements into field selection, access rules, retention jobs and verifiable deletion paths.

Follow information through its lifecycle

An organisation wants to translate an agreed retention schedule into working software controls.

A failure to account for

The main record is deleted while a searchable export remains accessible.

Illustrative scenario, not a customer case study.

Quality, security & governance

Implement the lifecycle of the information you hold.

Data flows

Document which personal information is collected, where it moves and which services process it.

Retention behaviour

Implement agreed retention and deletion rules across primary stores, exports and operational copies.

Access and disclosure

Review permissions, logs and support workflows for unnecessary exposure of personal information.

A policy needs an operating control

The fragile approach

Write a policy without changing the system

The application can continue collecting unnecessary data or retaining copies outside the documented process.

The intended approach

Connect policy decisions to technical controls

Give each data class an owner, a purpose, a retention rule and evidence that the rule is enforced.

Prepare the conversation

What needs attention in your system?

Select the areas you want to discuss. Download the list to share with your team.

Document which personal information is collected, where it moves and which services process it.

Implement agreed retention and deletion rules across primary stores, exports and operational copies.

Review permissions, logs and support workflows for unnecessary exposure of personal information.

0 areas selected

The business sets retention requirements with appropriate advice. Engineering identifies technical constraints and implements the approved rules consistently.