Data

Your data is leaving without a breach

Most leakage is not a hacker. It is a form, a tracker, a 'free' tool, and a company that sells the residue.

17 September 2026 · 7 min

Breach is the loud word

Boards prepare for ransomware. They rarely ask who already has a quiet copy of the customer list because a marketing pixel, a browser extension, or a SaaS trial ingested it last Tuesday. That is still a disclosure. It just does not make the evening news.

Large platforms make a living from this residue: search terms, device graphs, 'similar audiences', location pings. You do not have to be hacked for the data to move. You only have to click Allow, or forget to untick a box.

Where it actually leaks

Work happening in a personal Gmail. A spreadsheet in a consumer cloud with link sharing on. A chatbot that trains by default. A CRM connected to three ad networks. A 'free' PDF tool that uploads the file to another continent.

UK GDPR still applies. If you cannot name the processor, the purpose and the deletion date, you should not put the file there. That is not ideology. It is the same catalogue work we do on warehouses: source, owner, grain, destination.

A short check

List the tools that touch personal data. For each one: who is the controller, where is it hosted, is there a contract, can you export, can you delete. If three of those answers are blank, that is the leak. Fix the list before you buy another dashboard.

Related service: Data insights & strategy

Tell us the problem. We’ll tell you if we can help.

A short conversation is usually enough to know whether this is a two-week discovery or a longer piece of work. No pitch deck.

Book a conversation