Design Pattern · 2026-09-15
Deletion is the sharpest privacy test
A verified end-to-end deletion exercises the data map, the vendor list, the backup policy, and the derived-data problem at once. Few organisations pass it on the first attempt.
Under the pillar The dangers of data privacy theatre
The exercise
Seed a synthetic subject through the normal front door, let it propagate for a full cycle including analytics and vendor exports, then submit a deletion request through the ordinary channel. Afterwards, search for the identifiers everywhere: primary stores, warehouses, logs, caches, backups, ticketing systems, and vendor environments.
Record what remains, why, and whether the remaining copies are consistent with the published notice. The result is usually the first honest data map the organisation has had.
The limits of this test
A passed deletion test says nothing about access control, consent enforcement, or re-identification risk. It proves one property well.
Put this to work
Deletion is the sharpest privacy test application record
Apply Deletion is the sharpest privacy test to a real piece of work and record what happened.
- For
- Practitioners, researchers, founders, and operating leaders.
- What you keep
- A deletion is the sharpest privacy test application record you can review, revise, and send.
- What counts as sound
- Names a real setting
- Shows the work before and after
- Records exceptions
- Uses an observable result
- Ends with keep, revise, or stop
The result is a working analysis. Check it against source evidence and qualified judgment.
Nothing entered here is stored or sent. Review the prompt before sharing confidential, personal, patient, or privileged information.
Review the prompt
You can leave any field blank. The prompt will mark it as not provided.
If the record survives your review, send the question, evidence, unknowns, and requested next step.
