Onboarding copies both sides of ID cards; customer forms ask for home addresses "just in case." Fields kept for maybe-later are inventory for privacy incidents. Minimum necessary is concrete: collect only what the current process requires, visible only to roles that need it, delete or mask when purpose ends. Applies to employee and customer data—not only customer protection in marketing copy.
Compliance is not a consent checkbox. Fields, permissions, and retention must live in the system.
Three Questions Before Collection
Can this transaction proceed without the field? Must this role see the full value? After how long must the original no longer be kept? If any answer is no, the field does not enter the main table. Use receipts instead of image copies where possible; store last four digits, not full numbers.
- Employee: salary, health, and family data isolated from attendance—no export by default.
- Customer: IDs and bank cards only at legal payment/customs steps—sales follow-up cannot see them.
- Log access; alert on abnormal bulk queries.

Permissions and Retention Beat Promises
Disable accounts on departure day; revoke collaboration when projects end; auto-mask attachments past retention. The XYN digital intelligence system trims fields by role; sensitive items need separate authorization. When minimum necessary is default, audits shorten—there are fewer extra stores to explain.
Delete the maybe-later columns first. After that, the policy manual finally matches the system.
