gdpr
Safeguard articles tagged "gdpr" — guides, analysis, and best practices for software supply chain and application security.
15 articles
Soft-Deleted Records Are Still Reachable
A soft delete sets a flag and leaves the row in place, which means every single query, export, search index, and cache that touches that table has to remember to exclude it. One that does not is a path where a user's deletion was never actually honored.
Deleting a User Is Harder Than You Told the Customer
The row is soft deleted, a replica has it, the search index has it, last night's backup has it, the warehouse has a copy with different keys, and two vendors you forwarded it to still hold it.
A Vendor Just Told You They Were Breached
The notification is vague, late, and does not say whether you are affected. It starts several clocks, and one of them may be a 72-hour regulatory deadline that runs from when you became aware, not when their investigation finishes.
Watch Your Own Session Replay and Read Every Field
The recording is a reconstruction of the rendered page, so anything that reached the browser is a candidate, not just what the user typed. Masking covers the fields somebody remembered to cover.
The Export Button Is the Shortest Path From Account to Your Data on a Laptop
Every other endpoint is paginated. Export deliberately is not. It ships as a feature request, reuses the read permission, and is almost never reviewed as a data egress channel.
Your Subprocessor List Is Out of Date and That Is a Contract Problem
It was written for your first enterprise contract, it has three entries, and since then you added error tracking, support tooling, analytics and a model provider your product calls on every request.
Your Staging Environment Has Production Data In It
Nobody decides to put customer data in staging. It arrives through a restore for realistic testing, a debugging export, an analytics pipeline, a laptop dump. The copies inherit none of production's controls and never expire.
Data Residency and Security: FAQ
Where your data lives, what actually leaves your boundary, region pinning, customer-held keys, and how residency differs from sovereignty in a security platform.
GDPR for software developers: privacy by design in practice
GDPR is not just a legal team's problem. Data protection by design, security of processing, and processor due diligence all translate into code, dependencies, and architecture. Here is the developer's view.
Application Security Compliance overview (PCI DSS, HIPAA,...
PCI DSS 4.0, GDPR, FedRAMP, SOC 2, ISO 27001, NIST 800-53, and DORA now demand application-layer evidence. Here is what each requires and where scanner-only tools fall short.
Cloud Data Compliance: A Practical Guide to Getting It Right
Cloud data compliance is the practice of meeting legal and contractual rules for how data is stored, processed, and protected in cloud environments. Here is how to make it real.
Odido Telecom Breach: 6.2M Dutch Customers, Salesforce, and No Compensation (May 2026)
Odido, the Netherlands' largest mobile operator, exposed 6.2 million customers' data, including IBANs and ID details, via a vishing-driven Salesforce intrusion. In May 2026 the company ruled out compensation as mass claims mounted.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.