← ClaudeAtlas

cx-data-minimisation-reviewlisted

Use to find personal data support collects and stores that nothing actually uses, and to stop collecting it. Trigger for "do we collect too much data", "which fields do we actually use", data minimisation review, "why do we ask customers for this", reducing breach exposure, or a form that grew a field every quarter.
rulebase-co/rulebase-skills · ★ 1 · Data & Documents · score 72
Install: claude install-skill rulebase-co/rulebase-skills
# Data minimisation in support Support forms and ticket schemas grow. Every incident adds a field, every integration adds a property, every team adds a custom attribute — and nothing is ever removed, because removing a field feels riskier than keeping it. The result is a system holding personal data with no current purpose. That is both a compliance problem and, more concretely, **the single cheapest way to reduce the impact of a future breach**: data you do not hold cannot be exposed. This is the least glamorous analysis in the compliance set and one of the highest return-on-effort, because the findings are usually uncontroversial once someone actually looks. ## Inventory, then test for use List every field where personal data can land: - Ticket and conversation fields, standard and custom - Contact and customer record fields - Intake and contact-form fields, per form and per channel - Fields populated by integrations - Fields populated by automation - Free-text fields, which can contain anything - Attachments, and what customers are asked to attach Then, for each, establish **whether anything uses it**: - **Is it populated?** A field empty in 95% of records is either unused or inconsistently used, and both are findings. - **Is it read?** Query it in reports, dashboards, automations, routing rules, exports and integrations. **A field written by everyone and read by nothing is the target.** - **Is it read by a human?** A field displayed on a screen nobody looks at