What goes wrong repeatedly.
NOT KNOWING WHAT DATA YOU HOLD
Every other obligation becomes impossible.
RELYING ON CONSENT FOR EVERYTHING
Including things the person cannot realistically refuse.
BUNDLED CONSENT
Invalid, and easily challenged.
COLLECTING FIELDS WITH NO PURPOSE
Risk with no benefit.
PRIVACY NOTICES THAT DESCRIBE NOTHING
Vague language that tells the reader nothing.
NOTICES THAT DO NOT MATCH PRACTICE
A representation that is inaccurate, and actionable.
NO RETENTION SCHEDULE
Data kept forever by default.
PRODUCTION DATA IN TEST ENVIRONMENTS
A serious and common exposure.
SHARED LOGINS
Attribution impossible, undermining every other control.
ACCESS NEVER REVIEWED
Permissions accumulating for years, including for departed staff.
NO PROCESSOR AGREEMENTS
A straightforward gap, easily found.
IGNORING CROSS-BORDER TRANSFERS
Nearly every business makes them, and few document them.
MARKETING AFTER AN OPT-OUT
The commonest complaint of all.
NO BREACH PLAN
Missing a short notification deadline while deciding who decides.
TREATING BACKUPS AS OUTSIDE SCOPE
They contain everything.
DOCUMENTATION DESCRIBING PRACTICES NOBODY FOLLOWS
Evidence against you rather than for you.