Collect Only What You Need and Know Where It Lives
List the exact data points captured at sign-up, checkout, and support. Remove birthdates, middle names, and unnecessary addresses if not required for service or law. Map where each item is stored—email, CRM, payment processor—and set deletion timers. Minimization reduces exposure during breaches and shortens compliance questionnaires. A photographer stopped storing raw ID scans, replacing them with order numbers, and immediately shrank both risk and administrative overhead.