Obligations when data moves.
WHAT TO ESTABLISH
What personal data flows, to whom, and why.
WHY IT MATTERS
Sending data to a third party creates obligations, whatever the contract says.
WHAT TO MINIMISE
The fields sent.
WHY
Sending a whole record when three fields are needed expands exposure without benefit.
WHAT TO DOCUMENT
Every external recipient of personal data What they receive Why Where they are located
WHAT AGREEMENTS ARE USUALLY REQUIRED
A written arrangement covering purpose, security and deletion.
WHAT TO CHECK ABOUT PROVIDERS
Where data is stored Whether it is used for anything else How long it is retained Whether it is shared onward
WHY RETENTION MATTERS
Data you deleted may persist with them.
WHAT TO ESTABLISH
How deletion propagates.
WHAT TO BUILD
A way to remove a person's data from every connected system.
WHY
Deletion requests apply across the chain, not only your database.
WHAT TO BE CAREFUL WITH
Logs containing personal data Webhook payloads landing in third-party tools Test data copied from production
WHAT TO NEVER SEND TO AN EXTERNAL SERVICE
Data you have no permission to share.
WHAT TO TAKE ADVICE ON
Your obligations, which vary by jurisdiction.