Minimisation and retention limits
The most effective measure remains not keeping what you no longer need. It is also a direct obligation under privacy law.
RISK · DATA BREACH
The data you do not keep is the data that cannot leak.
A breach does not always involve a sophisticated intrusion. A cloud storage bucket left open, a database exposed without a password, a former employee whose access was never closed, a client file sent to the wrong address: most of the breaches we see come from there. The harm, however, is identical — loss of trust, notification obligations and sometimes lost contracts.
A storage service made public to unblock someone, an admin interface reachable from the internet, a test database filled with real customer data.
Employee departures, finished contractors, service accounts created for a project and never disabled.
Exports to a spreadsheet, sends to a personal mailbox, backups on unencrypted media.
The breach is often reported by a third party — a researcher, a client, a journalist — rather than detected internally.
These situations do not prove a breach happened, but they show nothing would prevent one.
The most effective measure remains not keeping what you no longer need. It is also a direct obligation under privacy law.
Each person accesses what their role requires, and nothing more. Broad "for convenience" access is the most frequent cause of exposure.
An encrypted file that leaves remains unreadable. It does not remove the duty to notify, but it radically changes the actual harm.
A quarterly access review catches forgotten departures, finished contractors and orphaned service accounts.
A bulk download at three in the morning or from an unusual country should raise an alert.
Privacy law requires keeping a register of confidentiality incidents and, in some cases, notifying. These steps are prepared before you need them.
These are the questions a client or an insurer will eventually ask you.
We map where your personal data genuinely sits and who can reach it today.
Map our data