Collect only what you really need

The most powerful principle is also the simplest: data you do not collect, you do not have to secure, store or delete. For every field in a form you may ask whether you really need it.

Know why you keep something

For every kind of data there should be a reason and a retention period. That sounds formal, but it prevents the situation where nobody knows why certain data is there and whether it may go.

Security is not an afterthought

  • Limit access to those who really need it.
  • Store and transmit data encrypted.
  • Keep track of who has seen or changed what and when.

Building these things in during the design costs little extra. Adding them afterwards is almost always more expensive and messier.

Mind where your data is

Where your data is physically located and which parties can access it is part of your responsibility. Ask this of every supplier, including handy tools you quickly add.

In short

Collect less, know why you keep something, build in security from the start and know where your data is. Then the GDPR is not a brake, but simply good craftsmanship.