A data journey with exits
Know what enters, where it goes and when it leaves.
A privacy notice cannot repair an undefined data flow. Before implementation, list each category of information, the person or system that provides it, the reason it is needed, the minimum fields, the people who can access it, the vendors or countries it may reach, how long it remains and what happens when a person asks a question about it.
Purpose and minimisation
Every field needs a named operational purpose. Optional information should look optional. Sensitive records, identity information, location, financial details, children’s information and regulated-sector data receive separate scrutiny. Test data should be invented or safely prepared rather than copied from production by convenience.
Access and cross-border handling
Document user roles, administrator access, support access, hosting, analytics, email, backups, integrations and subcontractors. Remote delivery from the United States may create cross-border questions that require current Ethiopian requirements and qualified advice. The implementation must not imply that encryption or a contract automatically resolves every legal question.
Retention, deletion and recovery
Set an operating retention rule and a safe deletion method. Backups need their own retention and restoration test. Incident preparation names who receives an alert, how access is contained, what evidence is preserved, who makes notification decisions and how service continues while the event is investigated.
AI boundary
Do not send personal or confidential information to an AI service merely because an interface makes it easy. Record the approved source, provider behavior, permissions, output reviewer, evaluation cases and fallback. High-impact decisions require accountable human review.