Published
Privacy, surveillance, and what never to type
A short, usable list you can hand to your staff this afternoon, and the reasoning behind it.
What belongs to you
The list
Print it. Put it where people work. This is the single highest-value governance artefact most organisations do not have.
- Names attached to a service someone receives from you
- Health information of any kind
- Financial account numbers, card numbers, tax identifiers
- Immigration or citizenship status
- Anything a person told you in confidence
- Passwords, keys, or credentials
- Case notes, incident reports, or disciplinary records
- Unpublished cultural or community knowledge
What it cannot do
Why the free tier is the risk
Consumer accounts and business accounts of the same product frequently have different data terms. Staff do not know this, and reasonably assume that a tool the organisation talks about is a tool the organisation has vetted.
If you have not chosen the tools, your staff have chosen them for you, on the free tier, with whatever terms come attached.
What you carry
Surveillance is not only a vendor question
For organisers in particular, the relevant question is not only what a company retains but what can be compelled from it. Assume anything held by a third party may be produced under legal process, and design what you keep accordingly.
The practical form of this is discipline about what gets written down and where — not paranoia, and not a false sense that encryption alone resolves it.
Put it to work
Heirloom Shield Self-Assessment
A reflective assessment across seven domains of sovereignty. Not a certification.
Open the tool