Ledger section 03 · Data Purpose before collection
FI Continuity Ledger Faith Forge Labs

A data map people can operate

Follow the information from entry to exit.

A privacy notice cannot repair an unknown data flow. Before launch, the project should be able to explain what enters the service, why it is needed, where it is stored, which vendors touch it, who can retrieve it, when it is removed, and what happens when something goes wrong.

1. Collection and purpose

List every form, account field, uploaded file, tracking event, support message, payment reference, device detail, and generated record. Connect each item to a specific business purpose and avoid fields that are merely convenient to collect. Record optional and required fields separately.

2. Access and movement

Draw the route from browser or device to application, database, email, analytics, payment processor, automation service, support tool, and backup. Name the organisation that controls each account. Record administrative roles, service accounts, logs, exports, and transfers outside Finland or the European Economic Area for qualified review.

3. Retention and deletion

Retention is an operating action, not a sentence in a policy. Define what starts the period, whether the source record and copies follow the same rule, how deletion is executed, which evidence is retained, and who reviews exceptions. Test a real deletion or anonymisation path before claiming that it works.

4. Requests and incidents

Give staff a route to identify a requester, locate relevant records, preserve case notes, involve qualified privacy leadership, and deliver the approved response. Incident preparation should identify detection signals, containment access, evidence preservation, communication ownership, vendor escalation, recovery, and post-incident learning.

5. Development safeguards

Use minimal test data, protected secrets, role-based access, reviewable logs, dependency maintenance, backups, controlled deployments, and documented rollback. AI features require an additional record of source data, model or service provider, output retention, evaluation, human review, and prohibited use.