UK GDPR for analytics teams: five habits that keep you safe

This article is general guidance, not legal advice. If you handle sensitive data, speak to your data protection officer.
1. Collect less
If an analysis does not need names, do not load them. The safest personal data is the data you never held.
2. Mask by default
Replace names and email addresses with a stable ID in your reporting layer. Analysts can still count and compare, and a leaked extract tells an attacker very little.
3. Know where it lives
Keep a simple register of which systems hold personal data. When a subject access request arrives, you will know where to look.
4. Set a retention period
Decide how long each dataset is kept, and delete it on schedule. Old data is a risk with no benefit.
5. Log access
Know who looked at what. Audit logs are boring until the day you need them, and then they are the first thing a regulator asks for.
None of this needs expensive software. It needs a written rule, an owner and a monthly check.

