Ask most organisations who owns their data problem and the answer is the legal, risk or compliance team. On paper that makes sense: privacy is a legal obligation. In practice, it’s the reason nothing gets deleted.
I’m not a privacy lawyer. But I’ve spent close to a decade in infrastructure, engineering and cyber security, then four more years in data, and that shows up in a specific way: I can tell you where the data lives, who can reach it, and what happens when you flip a switch. A lot of people running data programmes today can’t, because that was never their training.
Lawyers Keep Options Open. That’s The Problem.
Lawyers manage risk by keeping their options open. A record you still have can be relied on later. One you’ve deleted can’t. That instinct is sound for contracts. It’s the wrong instinct for a warehouse of old data nobody’s looked at in a decade, because in that case holding onto the record is the risk, not deleting it. If the only person making that call is trained to worry about the downside of deleting, and nobody is weighing the downside of keeping, everything stays. Not because anyone decided it should. Because nobody was in a position to decide it shouldn’t.
Know where your stuff is, know who has access to it, secure it well enough. That’s mattered since the dawn of IT.
“We’ve Tried This Before And It Didn’t Work”
That’s usually true, just not for the reason people think. What was tried was a paperwork exercise: a policy and a list of data typed up from a spreadsheet. What wasn’t tried was someone actually going into the systems themselves and working out what could safely be turned off.
Where To Start
The fix isn’t to sideline legal. It’s to pair two questions instead of relying on one. Legal is best placed to answer: what are we obligated to do? An engineer is best placed to answer: where does this data live, and what happens if we act on it? Most organisations have plenty of the first answer and almost none of the second.
