Building the data-rights machinery a privacy regime actually requires
The situation
A product that collects personal data and was built before anyone had to think about it. The data sits in the main database, and also in application logs, analytics events, a support tool, an email platform, a spreadsheet somebody exported eighteen months ago, and backups nobody has inventoried. Then a deletion request arrives, or a prospect sends a security questionnaire, and the honest answer to “where does personal data live” turns out to be nobody’s job to know.
How I'd approach it
Discovery before building anything. Map where personal data genuinely resides — including where it has leaked to, which is almost always logs, analytics payloads and third-party processors rather than the tidy columns someone expected. Then build the mechanics: subject access export, deletion that reaches every store rather than just the primary table, consent capture that records what was agreed and when, retention rules enforced by a scheduled job instead of by a policy document, and an audit trail that can evidence what happened. Where deletion conflicts with a legitimate need to retain — financial records being the usual case — the answer is pseudonymisation, and which fields that covers is a decision for your counsel, not for me.
What usually bites
Backups are the genuinely hard problem. A deletion request runs headlong into immutable backup media, and the workable answer is normally documented rotation with deletion reapplied on restore — but that is a position your lawyer signs off, not one an engineer should be inventing. The other reliable surprise is free text. Users type personal data into support tickets, internal notes and description fields, and no schema-level mapping catches it.
What I'd cut first
A self-serve privacy dashboard for end users. Handle requests through a documented internal process first and automate intake once volume justifies it — the obligation is to respond properly within the window, not to respond through a portal.
When I'd tell you not to
If you don’t yet have a lawyer or DPO engaged, start there rather than with me. I build the mechanisms that carry out a legal position; I don’t determine what that position should be, and any technical supplier who offers to decide your lawful basis is selling something they can’t stand behind.
