Customer information accumulates across systems, phones, mailboxes, spreadsheets, and paper without anybody deciding it should. Finding where it lives is the prerequisite for protecting it or deleting it.

Why this is worth an afternoon

Every protection depends on knowing what exists.

You cannot secure, delete, or answer a question about information you have forgotten you hold, and privacy obligations apply to it regardless of whether you remember it.

The exercise is also the one that reveals the genuine risks, which are almost never in the system somebody thinks of first.

Where it actually is

The list is longer than expected and most of it was never a decision.

The spreadsheet and the phone are where most small businesses have exposure they have never considered.

The exercise

  1. List every system the business uses, from the card statements and the connected applications list.
  2. For each, ask what customer information it holds, and roughly how far back.
  3. Search your own email and storage for exports, lists, and attachments.
  4. Ask staff what they keep and where, without blame, since the answers are informative.
  5. Note anything on paper.
  6. Write it down as a single page.

The fourth step is the one that produces surprises. Staff maintain their own lists, notes, and photographs because it made a job easier, and nobody asked.

What counts as sensitive

Worth being clear about, since the risk is not evenly distributed.

Names and phone numbers are ordinary. What raises the stakes: home addresses combined with information about when people are away, photographs showing the inside of properties, alarm codes or key locations, health information, financial details, and identification documents.

Trades hold more of the second category than they realise. A business with photographs of customers' homes, notes about access, and a schedule of when people are out is holding something that would matter if it were exposed.

Payment card details should not be held at all, in any form, including on paper or in an email somebody sent.

What to do with what you find

Three responses, applied per category.

Delete it, where there is no reason to hold it. This is most of what the exercise finds, and the retention question is settled separately.

Consolidate it, where the same information is in five places. Fewer copies means fewer things to protect.

Protect it properly, where it must be kept: in a system with access control rather than a spreadsheet, on encrypted devices, and accessible only to people who need it.

The consolidation step is undervalued. A business holding customer records in one system rather than scattered across four has reduced its exposure without deleting anything.

The third parties

The part businesses forget entirely.

Your mailing platform holds your list. Your booking system holds customer details. A contractor may have been given access. A previous web developer may still have a copy.

Under privacy legislation, information transferred to a third party for processing generally remains your responsibility, which means their handling of it is your concern rather than theirs alone.

Practically: know who holds what, know where it is stored, and remove access for anybody who no longer needs it, which is a task that never happens on its own.

Being able to answer

The obligation people do not anticipate.

An individual can generally ask what personal information a business holds about them and request access to it, subject to exceptions, under Canadian privacy legislation.

A business that has never mapped its data cannot answer such a request, and the request is not the moment to start looking.

Having the single page means the answer takes an hour rather than a week, and the applicable privacy commissioner is the reference for what the obligation actually requires.

Keeping it current

The page is worth revisiting when anything changes.

A new system, a departing employee, a new contractor, or a change in what you collect are each a reason to update it, and an annual review catches whatever was missed.

None of this requires expertise. It requires an afternoon and a willingness to look in places nobody has looked, and it makes the retention decisions actionable, which is the question of what should have gone already, as set out in how long to keep what.


Frequently asked questions

Why map what you hold?

Every protection depends on it. You cannot secure, delete, or answer a question about information you have forgotten you hold.

Where does customer data actually live?

Systems, the website form database, email, phones, spreadsheets, cloud storage, paper, third parties, former employees' devices, and backups.

Which step produces surprises?

Asking staff what they keep and where. People maintain their own lists, notes, and photographs because it made a job easier, and nobody asked.

What raises the stakes?

Home addresses combined with when people are away, photographs of property interiors, access details, health or financial information, and identification documents.

What should be done with what you find?

Delete what has no reason to exist, consolidate duplicates so there is less to protect, and properly secure what must be kept.

Why do third parties matter?

Information transferred to a third party for processing generally remains your responsibility, so their handling of it is your concern.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

No idea where customer information actually lives?

We map it in an afternoon, which is what makes deleting and protecting it possible at all.

Start a Conversation