Data Privacy, inside the lifecycle
Privacy is a lifecycle property
Four properties carry almost all of it, and each one is a lifecycle control rather than a document.
Purpose: every record is held for a stated reason, and the reason is recorded where the record is rather than in a register nobody opens.
Access: who may see it is scoped by role and by case, so nobody administers a list by hand and nobody has access because they once needed it.
Retention: the record leaves when its purpose ends, applied as a rule the system runs rather than as a decision under time pressure.
Traceability: what happened to the record, and who did it, is answerable without an export and without a specialist (International Organization for Standardization, 2016).
Under both the European regime and the Swiss one, holding personal data past its purpose is the breach, rather than an untidiness that precedes one (European Union, 2016) (Swiss Confederation, 2020).
What this looks like when it works
A subject access request is answered from a search rather than from a committee. A leaver’s file disposes of itself on schedule without anyone remembering. A department that wants to keep something longer has to say what for, and the answer is recorded rather than assumed. And nobody has to trust that the rule was followed, because the system that applied it says so.
Why privacy programmes stall
Two patterns, and we have seen both more than once.
The first is a policy written to a high standard and applied to nothing, because no system was ever configured to enforce it. It survives an audit of documentation and fails an audit of practice.
The second is a tooling purchase made before the estate was inventoried, so the tool enforces rules on the twenty per cent of content that was migrated into it while the shared drive keeps the other eighty. Both are avoidable, and both are expensive to unwind after the fact.
Where this sits
This is the privacy half of information governance, applied to the same records that records management governs. The obligations that arrive from outside, including the newer ones attached to AI, are set out under regulations and compliance.
The useful first question is not what your policy says. It is whether you could produce every record about one named person inside a working day, and show what happens to them next.