← All writing

Never store data you don't need

On this page

TL;DR: If you’ve been a victim of identity theft, or think your data might have been misused, skip to what to do. It’s critical that you protect yourself, especially when companies aren’t doing it for you.

I’ve filled out a lot of forms that want my date of birth. A gym waitlist. A newsletter. A form to book a boiler service. I still don’t know why the boiler man needs to know how old I am.

Sometimes there’s an explanation: “reporting” or “analytics”. Fine. What report? How much detail does it need? And why are you keeping the answers forever?

I suspect the flow at plenty of small businesses goes like this. I fill out a form. The form exports to a spreadsheet. My details then pick up a small property portfolio. Someone’s laptop. Their inbox. A shared drive. The backup of the shared drive.

That matters because your name, address and date of birth are most of what someone needs to pretend to be you. They’re the questions your bank asks when you ring up. They’re what a lender checks when someone applies for credit in your name. Every extra copy is another way for them to leak: a laptop left on a train, a hacked inbox, a shared link sent to the wrong person.

If you want to know which parts of London your customers come from, you can count them by area. You don’t need a permanent list of their front doors. Ask for the area, or cut the address down to the area before it reaches the spreadsheet. If all you need is a count, keep a count.

A boiler engineer needs my address to turn up. That doesn’t mean every report about the business needs it too.

Every box on your form is something you now have to protect. Your first security decision happens when you design the form.

Stop passing secrets around

A contractor once handed me a paper form with boxes for my card number, the expiry date and the three digits on the back. Someone in an office would type them into a card machine later. Then the form would go somewhere. A drawer, a folder, a bin.

That card number, expiry date and those three digits are everything an online shop asks for. Anyone who sees the form, in the office, the post room or the bin, can shop online as me. Criminals did exactly that 3.2 million times in the UK in 2025, taking £423.5m.1 You find out when the statement arrives. Then you cancel the card and update it everywhere you’ve ever used it.

The card industry’s own rules ban keeping those three digits after the payment goes through.2 Paper counts.

Reading your card details over the phone has much the same problem. You’re giving someone details they could use again, and trusting everything that happens next. Who else hears it? Is the call recorded? Where do the notes end up? Anyone who hears those numbers, or finds the notes later, can do exactly what the person who finds the paper form can.

I’d much rather approve one specific payment in my banking app. This shop, this amount, right now. The person on the phone shouldn’t need details that could be used for another payment later. An approval works once. A card number works until you cancel it.

The same idea works outside payments. A sensitive request needs proof tied to that exact request. A familiar name, a convincing document or an official-looking email address isn’t enough on its own.

In September 2026, Revolut handed customer information to a fraudster whose requests came from a real government email address.3 The fraudster walked away with passports, driving licences and possibly selfies and bank statements. That’s most of what you’d need to open an account as someone else. Those customers can get a new card. They can’t get a new face.

A real email address doesn’t prove a request is genuine. For anything sensitive, I’d want to check back through a route you already trust, and confirm the person asking is allowed to ask. Ringing the agency on a number you already hold is one good way to start.

And I’d want there to be much less to hand over in the first place.

Check the one fact you need

Say I’m buying a bottle of wine online. That’s the example. It’s always been the example. I don’t know what else you thought I meant by “websites that need to know you’re over 18”, and frankly I’m offended.

The wine shop has one very small question: is this person over 18? Somehow, answering it can involve uploading a document with my name, my photo, my date of birth and my passport number.

The question has a yes or no answer. We send a passport.

Checking who someone is and letting them back in are two different jobs. You only need to check the passport once. After that, you only need to know the same person has come back. Uploading the same passport to the next website repeats the first job and leaves another copy lying around to steal.

A stolen passport scan is worth a lot to a criminal. Plenty of services still accept a photo of an ID to open an account, so a leaked scan can help someone open one as you. You can change a leaked password in a minute. Replacing a passport takes weeks, and your date of birth never changes.

In my earlier post I argued for keeping your proof of age on your own phone and sharing only what each website needs to know.4 That’s still where I’d go. Check the facts once, give the person something that proves them, and let them share only the answer.

Passkeys can protect that proof. They replace passwords with a key that lives on your phone, and you usually confirm it’s you with your face, your fingerprint or a PIN.5

But a passkey doesn’t know how old you are. And it can’t tell whether the person holding the phone is the person whose passport was checked. Kids pick up their parents’ phones. That isn’t a rare edge case. It’s a normal Tuesday. A 14-year-old who’s watched you type your PIN is now, as far as the wine shop knows, you.

Locking the proof to one phone and planning carefully for lost phones helps. An extra PIN helps a bit, but PINs get shared and watched. Four digits don’t solve identity.

We should be honest about those limits. They still aren’t a reason to leave everyone’s driving licence sitting in a support inbox.

If you’re building identity checks, here’s what I’d want

Delete the document

Check the document, pull out the facts you need, then delete it. Include the temporary copies, the logs, the support tickets and the backups in that plan. Every copy you keep can be stolen, and the forgotten copies are the ones nobody’s watching. Discord’s ID photos leaked from a customer service company, not from Discord itself.6

Where the law says you must keep something, write down exactly what, why and for how long. “Compliance” should mean a specific rule, not a forever folder full of passports.

Apply the same thinking to the facts you pull out. An age check has no reason to keep your country of birth. And the country that issued your passport isn’t necessarily where you live or what nationality you are. Decide which question you’re answering before you collect anything to answer it.

Even a full date of birth needs a reason. If the only question is “over 18?”, a yes doesn’t stop being true on your next birthday. If you need to answer more than one age question, design it so no website ever gets your actual birthday.

Make the next check easy

Once someone’s verified, link that to a passkey on their phone. Ask for their face, fingerprint or PIN each time it’s used.

Where sharing a phone is a real risk, lock the proof to one device. Plan for new phones and lost phones too. A careful first check is worth very little if someone can reset it with a convincing email to your support team.

The normal experience should be simple. See the request, approve it, carry on. Uploading a passport again shouldn’t be the price of using the internet.

Answer small questions

Let a website ask an approved question like age_over: 18. Send back a signed answer that only works for that website, only once and only for a few minutes. The website should check all three.

If a website genuinely needs to recognise you again, give it an ID that only works for that website. If it doesn’t need one, don’t send one. An age check shouldn’t turn into an account that follows you around the internet. If every website gets the same ID for you, they can join up what you buy, read and watch into one profile, and sell it.

Separate IDs stop websites comparing notes about you. They don’t stop the checking service from seeing every website you visit, if every check goes through its servers.

I’d prefer a design where your phone shows the proof directly and the service that checked your passport never learns where you used it. Where that isn’t possible, keep as little as you can and say plainly what you can still see. “We don’t write it down” and “we can’t see it” are different promises. A list of every website someone proved their age to is exactly the list you’d least want leaked. Especially if it’s full of wine shops.

Control the questions

Yes or no answers can still give away a lot. Let a website ask “over 40?”, then “over 41?”, then “over 42?” and it can work out your exact age.

Approve a small set of questions for a stated reason. Check the combinations too, not just each question. Publish the list of who’s allowed to ask what.

Show the person who’s asking, what they’ll learn and why. The wine shop gets “over 18”. Just the wine shop. Obviously. A government department still needs a specific reason for anything more. Its name isn’t a blank cheque.

Make handing over data rare

If someone really needs the actual document, make that a separate process the person has to agree to. Collect it for that one request. Where you can, lock it on the person’s phone so only the checked recipient can open it.

Don’t keep a readable copy to make the next request easier. A readable copy is one more thing to steal, and one more thing a convincing fake request can get out of you. Just ask Revolut. Publish regular reports on what you held and what you handed over.

For data you never needed, “we didn’t have it” should be the only answer.

Be honest about fraud checks

If you need to spot the same passport being used twice, you can keep a scrambled fingerprint of the passport number instead of the number itself. Protect the key that does the scrambling, and limit who can run the comparison.

That spots a repeated passport, not a repeated person. People have more than one document, and documents get replaced. The fingerprint still links back to one person, too. Give it a clear purpose and a deletion date. Scrambling it isn’t permission to keep it forever.

Get ready for digital IDs

Accept government digital IDs where they meet the bar you need. The W3C is working on a standard that lets your browser ask your phone’s wallet for a digital ID.7

That’s useful plumbing. It doesn’t decide what you should be allowed to ask.

”We might need it” is never a purpose

My rule is simple. If you don’t need it, don’t ask. If you need it later, ask later. If someone says no, you should be able to explain why the service can’t work without it.

Asking at the moment you need something makes the trade obvious. I know why a delivery company needs my address when I’m ordering something. I have no idea why a newsletter needs my birthday.

UK law already says personal data must be “adequate, relevant and limited to what is necessary”.8 That should shape the database, the form and the export button. Too often, it only seems to shape the privacy policy.

At Flowstate, it goes in the bin

At Flowstate, we process a lot of sensitive data so we can report on it. We’ve had plenty of conversations about keeping it. For retention. For training. For analytics we might want one day.

My answer was firm. We’re not storing any of this, and we never will.

Our job is to process information and report on it. It isn’t to be opportunists about what’s inside it. So we built instant deletion into the system. The job finishes, the data goes.

I refuse to be the company with a horrific breach because we kept something we shouldn’t have. And frankly, it’s none of our business. You paid us to do a job. We do the job, then we throw the data in the bin.

That’s how I think every business should work. It should be instinct, not policy.

We know what the alternative costs

The examples aren’t hard to find.

The Optus breach in 2022 exposed personal details including passport and driving licence numbers. Australia’s privacy regulator says it seriously interfered with the privacy of 9.5 million people.9

In 2025, the Tea app leaked about 13,000 selfies and ID photos that people had sent in to get verified.10

That October, Discord said about 70,000 users may have had photos of their government ID exposed through a hacked customer service company. The photos had been used for age appeals.6

For the people in these breaches, it doesn’t end with the headline. Many will be watching their credit files for years. A leaked password can be changed. A leaked passport number, date of birth or face can’t, at least not easily.

If you collect ID to make your service safer, you need a reason for every extra day you keep it. Once the check or the appeal is done, keeping the document should need a specific reason and a deletion date.

Handing the check to another company doesn’t hand over the responsibility. The company you pick becomes part of your users’ risk. And frankly, you should be held responsible. Check that the companies you use follow these rules, and keep checking.

People get hurt

The ICO fined Capita a combined £14m after a 2023 breach in which details of 6.6 million people were stolen. That’s about £2.12 per person. Its first proposed fine of £45m would have been about £6.82 each.11

That isn’t compensation, and it isn’t the whole cost of the breach. Capita also paid for credit monitoring and a call centre, and the ICO cut the fine after looking at its improvements and the help it gave affected people.

Now look at it from the other side. A fraudster with your name, date of birth and address can apply for loans and credit cards in your name. Each one can be worth thousands of pounds, and nothing stops them applying for more than one. Cifas recorded more than 242,000 identity fraud cases in the UK in 2025, in what Cifas called a record year.12

The company pays £2.12. You can spend months proving the debt isn’t yours. If that’s you, here’s what to do.

In August 2025, Australia’s privacy regulator took Optus to court, counting one breach of the law for each person affected, with fines of up to A$2.22m for each one.9 That’s what the regulator is asking for, not what the court has decided.

My point is about incentives. Keeping data you don’t need should cost enough to reflect the risk it puts on the person it belongs to. Right now, that person has no say in how many copies exist and gets nothing from them existing.

It happens to people I know

Two friends sent me these while I was writing this post.

I was in the Optus breach. Never had an issue on my credit file before. It was pretty quiet since the breach, but a few weeks ago I had a loan with humm via appliances online delivered to an address in another state. Took me WEEKS to have it cancelled.

Matt C.

Someone’s had a wild time with a Gold Amex opened in my name. I hope they enjoyed their time in Newcastle and SYDNEY because I got your full statement, babe. I’ll be following up with the authorities

Josh T.

The Optus breach was in 2022. Matt’s loan turned up four years later. Stolen details don’t expire.

Hoarded data is a liability

Some investors look at a pile of customer data and see an asset. It might train a model one day. It might power a dashboard one day. It might impress a buyer one day.

That same pile is what ends up in the lawsuit. Equifax agreed to pay at least $575m, and up to $700m, after its 2017 breach exposed 147 million people.13 That bill lands on the company’s balance sheet, and on its investors. The upside was a maybe. The downside had nine figures.

And the people in that pile are the ones who get hurt first. The company pays once. They deal with it for years.

You don’t have to choose between understanding your business and protecting your customers. You have to be smart at collection time:

  • Count, don’t record. Add one to “sign-ups from Manchester this week” instead of storing a row per person with their postcode.
  • Roll up, then delete. Turn raw events into totals, then throw the raw events away.
  • Cut it down on the way in. Keep the first half of a postcode, the month someone joined, an age band.
  • Use IDs that expire. A random ID that changes every day still lets you count unique visitors. It doesn’t let you follow anyone for a year.

You still get the graph. You still see what people use, where they drop off and what they come back for. Nobody gets a list of names.

Start with the form

Some software has to hold sensitive information. Banks need records. Doctors need histories. A delivery driver needs somewhere to go. Those systems still need serious security.

But every box you didn’t need makes that job harder. Every export spreads the risk. Every “keep it just in case” puts off a decision and leaves someone else exposed.

Before you ask how to secure a database full of passports, ask why you’re building one.

I wanted to book a boiler service. You needed an address and a time. Start there.

If your data’s already out there

If you’ve had a breach letter, or you think your details have been misused, this is what I’d do.

If it’s already happened, and you’re looking at a loan or a bill you never took out, stop for a moment. It’s fraud. It isn’t your fault. It can be fixed. Debt a fraudster ran up in your name can be challenged, and there are free services whose whole job is helping you do that. If it feels like too much, talk to someone first. There’s a number for that below too.

Never pay for a credit report. Every country below lets you check for free. Sites that charge, or offer a “free trial” that turns into a subscription, are selling you something you can already get free. Watch for copycat sites that look official, too.

United Kingdom

Check your credit reports for free

There are three credit reference agencies. Lenders don’t all use the same one, so check all three.14

Look for accounts, searches or addresses you don’t recognise.

Lock it down

The UK has no single free credit freeze. You can get close by stacking these:

  • A password on your credit files. Ask each agency to add a password notice of correction. Lenders are asked to contact you for the password before approving anything in your name.
  • Cifas Protective Registration. A warning flag on your name so lenders do extra checks. It costs £30 for two years. It isn’t a credit report, and it’s the only paid thing on this list I’d consider.

Experian’s CreditLock only comes with a paid subscription and only covers Experian. I’d skip it.

If someone’s used your details

  • Report it to Report Fraud on 0300 123 2040 in England, Wales and Northern Ireland. In Scotland, call Police Scotland on 101.15
  • Call the lender on the number from its own website, not one from an email or text.
  • Tell your bank.
  • Keep a note of every call, reference number and letter.

Talk to someone

  • Victim Support: free on 08 08 16 89 111, 24 hours a day. They help fraud victims.
  • Samaritans: free on 116 123, any time, if it’s all getting too much.

United States

Check your credit reports for free

  • AnnualCreditReport.com is the only official site. You can check all three bureaus for free every week. You can also call 1-877-322-8228.16
  • Lookalike sites use misspellings of that address to sell you things. Type it carefully.

Freeze your credit

A freeze is free. It stops anyone opening new credit in your name, including you, until you lift it. Place one at each bureau:17

If someone’s used your details

  • Report it at IdentityTheft.gov. It’s the FTC’s official site, and it gives you a recovery plan.
  • Call the lender on the number from its own website.
  • Tell your bank.

Talk to someone

Australia

Check your credit reports for free

You can get a free credit report from each credit reporting body every three months.18 Check both:

  • Equifax: 138 332
  • Experian: 1300 783 684. illion is now part of Experian.

The OAIC’s guide explains your rights.

Ban your credit report

A ban stops your credit report being used or shared. It’s free and lasts 21 days. You can extend it, usually with a police or ReportCyber reference number.19

If someone’s used your details

  • Report it through ReportCyber.
  • Call the lender on the number from its own website.
  • Tell your bank and ask it to put a block on your accounts.

Talk to someone

Canada

Check your credit reports for free

Both bureaus give you your credit report for free online, by post or by phone.20

Lock it down

  • Quebec and Ontario: you can lock your Equifax credit report for free. It takes effect straight away.
  • Everywhere: tell both Equifax and TransUnion you’re a fraud victim, and ask your bank to flag your accounts.

If someone’s used your details

  • Report it to your local police and get a file number.
  • Report it to the Canadian Anti-Fraud Centre online or on 1-888-495-8501.21
  • Be wary of anyone who contacts you offering to recover your money for a fee. Fraudsters target victims twice.

Talk to someone

New Zealand

Check your credit reports for free

There are three credit reporters: Centrix, Equifax and Experian. All three give you a free report.22

  • The govt.nz guide links to each one.
  • Some offer to send it faster for a fee. Don’t pay. The free one is the same report.

Freeze your credit

  • Ask Centrix to suppress (freeze) your credit file, and tick the box to pass the request to Equifax and Experian.
  • A freeze starts at 10 working days, and you can ask to extend it.23

If someone’s used your details

  • Report it to Police on 105, or use the online form.
  • Call the lender on the number from its own website.
  • Tell your bank.

Talk to someone

  • IDCARE: free on 0800 121 068. A case manager will build a recovery plan with you.
  • 1737: free call or text 1737, any time, if it’s all getting too much.

Ireland

Check your credit report for free

Lock it down

  • Ask the Central Credit Register to add a notice of suspected impersonation to your report. It lasts 90 days.

If someone’s used your details

  • Report it to An Garda Síochána.
  • Call the lender on the number from its own website.
  • Tell your bank.

Talk to someone

Deutschland

Es ist Betrug. Es ist nicht Ihre Schuld. Es lässt sich klären. Zahlen Sie niemals für eine Bonitätsauskunft.

Bonitätsauskunft kostenlos prüfen

  • Die SCHUFA muss Ihnen nach der DSGVO eine kostenlose Datenkopie geben. Sie kommt in etwa einer Woche per Post. Auf derselben Website werden kostenpflichtige Produkte angeboten. Die brauchen Sie nicht.

Absichern

  • In Deutschland gibt es keine Kreditsperre. Ihre SCHUFA-Daten zu prüfen ist deshalb Ihr wichtigstes Frühwarnsystem.

Wenn jemand Ihre Daten missbraucht hat

  • Erstatten Sie Anzeige bei der Polizei. Die meisten Bundesländer haben eine Onlinewache.
  • Rufen Sie den Kreditgeber unter der Nummer auf seiner eigenen Website an, nicht unter einer Nummer aus einer E-Mail oder SMS.
  • Informieren Sie Ihre Bank.

Mit jemandem sprechen

  • WEISSER RING Opfer-Telefon: kostenlos unter 116 006, täglich von 7 bis 22 Uhr. Hilfe für Opfer von Straftaten.
  • TelefonSeelsorge: kostenlos unter 0800 111 0 111, rund um die Uhr, wenn Ihnen alles zu viel wird.

France

C’est une fraude. Ce n’est pas de votre faute. Cela peut se régler. Ne payez jamais pour consulter vos informations de crédit.

Consultez gratuitement les fichiers

La France n’a pas de bureau de crédit privé. La Banque de France tient les fichiers nationaux des incidents de remboursement (FICP) et des incidents de paiement (FCC).

  • Consultez-les gratuitement depuis votre espace personnel Banque de France, ou au 34 14.
  • Vérifiez Ficoba, la liste des comptes bancaires ouverts à votre nom, via votre messagerie sécurisée sur impots.gouv.fr.

Si quelqu’un a utilisé vos données

  • Portez plainte au commissariat ou à la gendarmerie. Le guide de Service Public explique la démarche.
  • Appelez l’organisme de crédit au numéro indiqué sur son propre site, pas à un numéro reçu par e-mail ou SMS.
  • Prévenez votre banque.

Parlez à quelqu’un

  • 116 006 : aide gratuite aux victimes, tous les jours de 9 h à 20 h.
  • 3114 : gratuit, 24 h/24, si tout devient trop lourd.

España

Es un fraude. No es culpa tuya. Tiene solución. Nunca pagues por un informe de crédito.

Consulta gratis tus informes de crédito

Si alguien ha usado tus datos

  • Denúncialo ante la Policía Nacional o la Guardia Civil.
  • Envía la denuncia y tu DNI a Equifax para corregir tu registro en ASNEF.
  • Llama a la línea de ayuda en ciberseguridad de INCIBE, el 017. Es gratuita y atiende todos los días de 8:00 a 23:00. También por WhatsApp en el 900 116 117.

Habla con alguien

  • 024: gratuito, a cualquier hora, si todo se te hace demasiado.

Italia

È una frode. Non è colpa tua. Si può risolvere. Non pagare mai per consultare i tuoi dati creditizi.

Controlla gratis i tuoi dati creditizi

  • La Centrale dei Rischi della Banca d’Italia è gratuita. Puoi fare richiesta online con SPID o CIE.
  • Anche CRIF deve darti i tuoi dati gratuitamente. Vende anche un servizio rapido da 39 €. Non ti serve.

Se qualcuno ha usato i tuoi dati

  • Sporgi denuncia alla Polizia Postale, alla Polizia o ai Carabinieri.
  • Chiama la società di credito al numero indicato sul suo sito, non a un numero ricevuto via e-mail o SMS.
  • Avvisa la tua banca.

Parla con qualcuno

  • Telefono Amico: 02 2327 2327, tutti i giorni dalle 10 a mezzanotte, se tutto diventa troppo.

Polska

To oszustwo. To nie Twoja wina. Da się to naprawić. Nigdy nie płać za raport kredytowy.

Najpierw się zabezpiecz

  • Zastrzeż swój numer PESEL w aplikacji mObywatel, na gov.pl albo w urzędzie gminy. To nic nie kosztuje. Od 1 czerwca 2024 r. instytucje finansowe muszą sprawdzić rejestr, zanim udzielą komukolwiek kredytu na Twoje dane. Działa to jak blokada kredytowa.

Sprawdź bezpłatnie swoje dane kredytowe

  • BIK to główne biuro informacji kredytowej. Na podstawie RODO możesz poprosić o bezpłatną kopię swoich danych. Płatne alerty nie są Ci potrzebne.

Jeśli ktoś wykorzystał Twoje dane

  • Zgłoś to na policję.
  • Zgłoś to do CERT Polska.
  • Poinformuj swój bank.

Porozmawiaj z kimś

  • Centrum Wsparcia: bezpłatnie pod numerem 800 70 2222, całą dobę, jeśli wszystko Cię przerasta.

Nederland

Het is fraude. Het is niet jouw schuld. Het is op te lossen. Betaal nooit om je kredietgegevens in te zien.

Bekijk gratis je kredietregistratie

  • Bekijk je BKR-registratie gratis op mijnkredietregistratie.nl met DigiD. BKR verkoopt ook een gewaarmerkt overzicht voor € 17,50. Dat heb je niet nodig.

Als iemand je gegevens heeft misbruikt

  • Meld het bij het Centraal Meldpunt Identiteitsfraude van de overheid. Zij kunnen namens jou contact opnemen met de betrokken organisaties.
  • Doe aangifte bij de politie via 0900 8844.
  • Waarschuw je bank.

Praat met iemand

Portugal

É uma fraude. Não é culpa sua. Tem solução. Nunca pague por um relatório de crédito.

Consulte gratuitamente o seu mapa de crédito

Se alguém usou os seus dados

  • Apresente queixa na PSP, na GNR ou na Polícia Judiciária.
  • Contacte a entidade de crédito através do número indicado no seu site oficial, e não de um número recebido por e-mail ou SMS.
  • Avise o seu banco.

Fale com alguém

  • APAV: gratuito através do 116 006, nos dias úteis das 8h às 23h. Apoio a vítimas de crime.
  • SNS 24: gratuito através do 1411, a qualquer hora, se tudo se tornar demasiado.

Wherever you live, these help too.

Use a different email address for everything

  • Use a separate email alias for each company. Apple’s Hide My Email, Fastmail’s masked email and similar services make this easy.
  • When one company leaks your details, you know which one it was. You can also switch that alias off.
  • Someone can’t take your email from one breach and try it everywhere else.

Use a different password everywhere

  • Use a password manager and let it make a new password for every site.
  • Turn on passkeys where they’re offered.
  • Turn on two-step login, and use an authenticator app rather than text messages where you can.

Lie on your security questions

Questions like “What’s your mother’s date of birth?” are a terrible idea. That answer is probably in someone’s breached spreadsheet already.

Treat the answer as another password. Use a different, made-up answer for each company. Think of the question as “What’s my mother’s date of birth according to Coutts?”, then give Coutts its own answer. Store it in your password manager.

Share your story

Matt and Josh already have. If this has happened to you and you’d like to share what it was like, get in touch. With your permission, I’ll add it here, with your name or without it.

If your company handles personal data

Delete by default. Keep nothing you don’t need, for no longer than you need it.

I’ve turned this post into a two-page checklist for your security and product teams. Every item comes from UK GDPR, the ICO, the OWASP Top 10 Privacy Risks or PCI DSS, with the source underneath. Print it, share it, stick it on the wall.

Delete by default: a personal data checklist for companies Collect less, keep it for less time, share less, and be ready. PDF · 37 KB · Download

Footnotes

  1. UK Finance: Fraud remains a national security threat as criminals steal almost £1.3 billion, Annual Fraud Report 2026. ↩

  2. PCI Security Standards Council: Can card verification codes/values be stored for card-on-file or recurring transactions? ↩

  3. TechCrunch: Revolut confirms customer data breach through fake government requests, 12 September 2026. ↩

  4. Will Hackett: Digital ID done right: verifiable claims without the surveillance ↩

  5. W3C: Web Authentication, Level 3, particularly user verification and credential backup state. ↩

  6. Discord: Update on a security incident involving third-party customer service, updated 9 October 2025. ↩ ↩2

  7. W3C: Digital Credentials, working draft, 4 September 2026. ↩

  8. ICO: The data minimisation principle, explaining Article 5(1)(c) of UK GDPR. ↩

  9. OAIC: Australian Information Commissioner takes civil penalty action against Optus, 8 August 2025. ↩ ↩2

  10. TechCrunch: Dating safety app Tea breached, exposing 72,000 user images, 26 July 2025. ↩

  11. ICO: Capita fined £14m for data breach affecting over 6m people, 15 October 2025. ↩

  12. Cifas: Fraudscape 2026 ↩

  13. FTC: Equifax to pay $575 million as part of settlement with FTC, CFPB, and states related to 2017 data breach, 22 July 2019. ↩

  14. MoneyHelper: How to check your credit report for free ↩

  15. City of London Police: Report Fraud service goes live ↩

  16. FTC: Free credit reports ↩

  17. FTC: Credit freezes and fraud alerts ↩

  18. OAIC: Access your credit report ↩

  19. OAIC: Fraud and your credit report and IDCARE: Credit bans in Australia ↩

  20. Financial Consumer Agency of Canada: Getting your credit report and credit score ↩

  21. Canadian Anti-Fraud Centre: What to do if you’re a victim of fraud ↩

  22. govt.nz: Check your own credit record ↩

  23. Office of the Privacy Commissioner: How do I freeze my credit information? ↩