HEINOUX Journal Portfolio

Journal

The customer data I was keeping for no reason

I went looking for what my business actually stores about people, and found years of information I had no reason to keep. What that audit changed about how I build.

By · · updated · 5 min read

The customer data I was keeping for no reason

I sat down to do a boring compliance task and ended up unsettled by it.

The job was simple: list everywhere my business holds information about a real person. Not the policy version of that list, the true one. Every drive, every inbox folder, every spreadsheet, every chat thread, every export I had ever downloaded and never deleted.

It took most of a morning, and the result was longer than I expected.

What was actually in there

Old lead lists from campaigns that ended. Quote documents with people's full contact details attached to deals that never happened. Screenshots of conversations I had saved because they were useful at the time and then never looked at again. Exports of contacts sitting in a downloads folder, months old, that existed only because I once wanted to check something in a spreadsheet.

None of it was sinister. Every single item had a reason at the moment it was created. What none of it had was a reason to still exist.

That was the uncomfortable part. I had not made a decision to keep any of it. I had simply never made the decision to delete it, and the two are not the same thing, even though they produce the same outcome.

The default is keeping

Software makes keeping easy and deleting hard. Storage is cheap, exports are one click, and nothing in a normal working day ever prompts you to ask whether you still need something. The result is that every business quietly accumulates a shadow archive of other people's information, held by default rather than by choice.

I had written a whole workplace policy about how our team should handle data and still had a downloads folder that contradicted it. The gap between what I had written down and what my actual file system contained was the honest answer to how compliant I was.

What I changed

Three things, and they are all unglamorous.

I deleted first, then organised. The instinct is to build a beautiful structure for everything you have. The better move is to get rid of what should not be there, then structure the small amount that remains. Roughly half of what I found went, and nothing broke.

I gave every store of data a stated purpose. Not a category, a purpose. Why does this exist, and what happens when that reason stops applying. Anything that could not answer both questions was not a record, it was residue.

I stopped exporting. Almost every stale file traced back to someone, usually me, pulling data out of a system to do one quick thing. The fix was making the system good enough that I do not need to. That was part of why I ended up building our own CRM and getting it wrong the first time. If the tool answers the question in place, the export never happens, and the copy never rots in a folder.

Why this is not really about compliance

I started because of the law. I finished for a different reason.

Holding information you cannot justify is a small, constant liability, and it sits on top of a much more ordinary problem: you do not actually know what your business knows. When customer information is spread over eleven places, you cannot answer a simple question about a client without hunting, you cannot hand the account to someone else cleanly, and you certainly cannot tell a person what you hold about them if they ask.

The compliance requirement and the operational requirement turn out to be the same requirement wearing different clothes. That is the pattern I keep running into, and it is why I keep saying that the work has to be mapped before any tool gets bought. You cannot automate around a mess you have not looked at.

The uncomfortable question

Here is the one worth sitting with. If a customer emailed you tomorrow and asked, politely, for a list of everything your business holds about them, could you produce it?

Not eventually. This week.

If the answer is no, that is not a legal problem yet. It is an operational one, and it is fixable in a morning. The legal version only arrives later, and it arrives on someone else's timeline.

My team wrote up the practical version of all of this as a POPIA compliance checklist for South African small businesses, with the statutory sources attached. This post is the same subject from the founder's chair, on the day I found out my own house was not in order.

Frequently Asked Questions

What made you audit your own data in the first place? A compliance task I expected to tick off in twenty minutes. Listing every place my business stores information about a person took a morning and turned up years of files I had never decided to keep, only never decided to delete.

How much did you end up deleting? Roughly half of what I found. Old lead lists, stale exports, quote documents for deals that never happened, saved screenshots. Nothing broke. Nothing was missed. The only thing that changed was that I could finally describe what I hold.

Is this a legal exercise or an operational one? Both, and that is the point. The same messy sprawl that creates compliance exposure is what stops you answering a simple question about a customer quickly. Fixing one fixes the other.

What is the single habit that prevents it recurring? Stop exporting. Almost every stale file started as someone pulling data out of a system to answer one question. If the system answers it in place, the copy is never made and there is nothing to rot in a folder.

More of the build, and the mistakes, at heinoux.nexbdm.co.za.

Want this kind of build for your business?

I build AI systems, custom company dashboards and automation for growing businesses.

Get your autopsy Email me