Data-protection questions every digital product should answer
Compliance is easier to build into a product than to retrofit onto one. Six questions establish whether the foundations are in place.

Data-protection obligations attach to what a product does, not to what its policy says. These questions surface the gap between the two.
What are we collecting, and why
A current data inventory — categories, sources, purposes — is the base document. Everything else depends on it, and it is usually out of date within two product cycles.
What is our lawful basis
Consent is one basis among several, and it is often the weakest choice for core product functionality. Record the basis for each processing purpose rather than assuming a single one covers everything.
Who else touches the data
Analytics, hosting, support tooling and payment providers are processors. Each needs a written processing agreement, and cross-border transfers need a documented position.
How long do we keep it
Indefinite retention is a decision, and rarely a defensible one. Set retention periods per data category and make deletion an implemented function, not an intention.
Can we respond to a data-subject request
Access, correction and deletion requests have timelines. Test the operational path before one arrives.
- Who receives the request
- How the data is located across systems
- How identity is verified
- Who approves the response
What happens in a breach
Detection, assessment, notification and record-keeping should be written down while nothing is going wrong. A breach is a poor moment to design a process.
This article is general commentary written for a demonstration website. It is not legal advice and should not be relied upon for any specific matter.




