Your company processes far more personal data than you realise
Ultimately, the customer database is just one part of a much broader ecosystem of personal information processed by the organisation. Behind it lies a constant flow of information circulating between different systems, applications, documents and third parties. Data is collected, stored, replicated and shared as part of the organisation’s day-to-day operations, often without a comprehensive overview of its entire journey.
Protecting customer data does not begin with a privacy policy or a consent form. It begins with a much more basic question: what customer data are we actually processing, and where is it? It seems simple, but in practice few organisations can answer it with certainty.
A customer can provide their information to a company in dozens of different ways: by filling in a form on the website, by sending an enquiry by email, by phoning, by making a purchase, by signing up to a loyalty scheme, by interacting on social media, or simply by speaking to a sales representative who jots down details in a spreadsheet. Each of these touchpoints generates data. And in most companies, that data ends up scattered across different systems, many of which were not designed to function as databases but have, over time, become exactly that.
The problem is exacerbated when we consider how many different areas of the business handle this information. Sales uses it to track opportunities. Marketing uses it to send out campaigns. Customer service consults it to resolve issues. Accounting processes it for invoicing. IT manages it within the systems. And in many cases, external agencies, email marketing platforms, payment processors and analytics tools also receive a copy. Each of these data flows involves data processing with its own purposes, its own risks and, in many cases, specific legal obligations of which the company is unaware because it has never mapped them out.
Identifying these processing operations is also essential for determining why the company is processing the data and what the legal basis is that legitimises each activity. It is often assumed that consent is the sole basis for processing personal data, when in fact there are multiple legal bases that may apply, depending on the purpose of the processing and the relevant regulatory framework. The performance of a contract, compliance with a legal obligation or a legitimate interest, amongst others, may constitute valid grounds without the need to obtain the data subject’s consent. Therefore, before requesting authorisations or drafting privacy clauses, the organisation must be absolutely clear about what processing it carries out, for what purpose it is carried out and what the legal basis is that underpins it.
Nor is it enough simply to know that data exists. It is necessary to understand what happens to it from the moment the customer provides it until it is no longer required. How is it collected? What exactly is it used for? Who has access to it? With which suppliers is it shared? Where is it stored and under what security conditions? How long is it retained? When and how is it deleted? Answering these questions enables organisations to map out the full lifecycle of customer information and identify vulnerabilities that would otherwise go unnoticed.
It is common for companies to spend time drafting privacy policies or consent clauses before they have completed this exercise. The result is that these documents are disconnected from reality. How can a company properly inform its customers about the use of their data if it has not even identified all the data processing operations it carries out? How can it guarantee that its customers’ data is secure if it does not know how many different systems the data resides on or who has access to it? Compliance does not begin with documents. It begins with understanding what is actually happening with the information.
The root cause of most problems relating to customer data protection is not malicious intent or gross negligence. It is a lack of knowledge. Before discussing consent, privacy policies or security measures, every organisation should be able to answer a seemingly simple question: do we really know what customer data we are processing? If the answer is not entirely clear, the first step is not to draw up more documents. It is to understand how information flows within the organisation. Only on the basis of that knowledge is it possible to build a robust, coherent data protection programme tailored to the reality of each organisation.