Purpose and minimisation
Inventory forms, accounts, logs, cookies, analytics, messages, files, derived values, and backups. Ask why each field exists, who uses it, and whether a less intrusive route works.
Data layer / purpose before collection
Privacy becomes implementable when purpose, fields, roles, suppliers, tracking, lifecycle, requests, security, and documentation have named owners. The responsible organisation and its advisers decide legal conclusions.
Inventory forms, accounts, logs, cookies, analytics, messages, files, derived values, and backups. Ask why each field exists, who uses it, and whether a less intrusive route works.
Name the organisation deciding purposes, every implementation or processing party, client owners, administrators, support teams, and the person approving notices or choices.
Trace hosting, analytics, communications, AI, identity, support, files, subcontractors, locations, contracts, credentials, and proposed transfer route for responsible review.
Record necessary and optional technologies, approved information, consent behavior when required, preference changes, denied-choice behavior, and evidence that the interface honors the decision.
Specify retention, deletion, backup expiry, access, correction, export, objection or other request intake, identity checks, exception ownership, and completion records.
Connect permissions, authentication, encryption decisions, logs, dependencies, recovery tests, incident response, owners, dates, technical evidence, and the maintenance record.
The Swedish Authority for Privacy Protection (IMY) is an official starting point. Faith Forge Labs can build approved controls but does not determine GDPR applicability, lawful basis, transfer compliance, or certification.
Data document
Follow it from collection to every supplier, staff view, decision, backup, request process, and eventual deletion.