Employee Approval: Privacy by Design for Contact Data
What privacy by design means for a contact discovery tool, and why enforcing it in the data model matters more than hiding fields on a screen.
Privacy by Design Is a Data Model Decision
GDPR asks organizations to build data protection into systems from the start, not bolt it on later. For many products, privacy means a setting, a permission or a hidden column. Those protections are only as strong as the next query that ignores them. Real privacy by design means the protection is part of how the data is stored.
Five Properties That Matter
Enforced in the database, not on a screen. Unreleased contacts sit in a physically separate store that every other read path refuses. They are not hidden fields one query away from visible.
Marketing sees counts, never contacts. Before release, Marketing sees who has contacts waiting and for how long. No name, no address, no company, no search and no export.
The employee grants access, and can take it back. Each employee connects their own mailbox on the mail provider's own consent screen and can revoke it at any time without asking anyone.
Unreviewed contacts are forgotten. Anything nobody acts on is deleted after ninety days, silently, with no pressure on the employee.
Sensitive mail is never read at all. Internal mail, human resources, unions, occupational health and legal are excluded before anything is read.
Who Can Change the Defaults
The safest setting is the default for every privacy control. Only the customer's own administrator can switch off employee approval, as a named, reasoned and permanently logged decision. The vendor cannot.
Evidence for Reviewers
A privacy review needs evidence, not assurances. RelationLens keeps an append-only log for the life of the account, makes every export re-downloadable for 24 months, and provides a readiness report and legal terms on request.