# Know where data goes and when it should leave.

Privacy & data handling

Map collection, access, retention and external processing so requirements can be translated into controls.

## Follow information through its lifecycle

Illustrative workflow.

- Collection: Required fields and a stated purpose
- Processing: Approved systems and access boundaries
- Retention: Deletion rules and recovery copies



## Make data handling an implemented behaviour

Map personal and sensitive information across applications, integrations, logs and backups. Turn agreed requirements into field selection, access rules, retention jobs and verifiable deletion paths.

Illustrative scenario, not a customer case study.

An organisation wants to translate an agreed retention schedule into working software controls.

Map primary records, replicas, exports, search indexes and backups. Define deletion behaviour for each destination and record exceptions such as an authorised hold.

Verification: Trace representative records through deletion and verify what remains in each documented location.

## Implement the lifecycle of the information you hold.

### Data flows

Document which personal information is collected, where it moves and which services process it.

### Retention behaviour

Implement agreed retention and deletion rules across primary stores, exports and operational copies.

### Access and disclosure

Review permissions, logs and support workflows for unnecessary exposure of personal information.

## A policy needs an operating control

### Write a policy without changing the system

The application can continue collecting unnecessary data or retaining copies outside the documented process.

### Connect policy decisions to technical controls

Give each data class an owner, a purpose, a retention rule and evidence that the rule is enforced.

## What needs attention in your system?

Select the areas you want to discuss. The HTML page can download your selections.

- [ ] Data flows: Document which personal information is collected, where it moves and which services process it.
- [ ] Retention behaviour: Implement agreed retention and deletion rules across primary stores, exports and operational copies.
- [ ] Access and disclosure: Review permissions, logs and support workflows for unnecessary exposure of personal information.

## Can engineering decide the legal retention period?

The business sets retention requirements with appropriate advice. Engineering identifies technical constraints and implements the approved rules consistently.
