layout: null --- GDPR & Data Security | Sandile Desmond Mfazi
Data Protection Framework

Enterprise-Grade Data Security & GDPR Alignment.

Strict adherence to the General Data Protection Regulation (GDPR) and the UK Data Protection Act is a foundational pillar of my architectural engagement model.

01. Zero-Extraction Policy

Client data is never hosted, downloaded, or replicated onto unauthorized offshore hardware. All development is performed securely via your organization's approved Virtual Desktop Infrastructure (VDI) or native cloud tenant.

02. Cross-Border Compliance

Operating from Botswana, international data processing is legally secured through the execution of Standard Contractual Clauses (SCCs), ensuring complete alignment with EU and UK data transfer regulations.

03. Principle of Least Privilege

During engagements, I request only the specific database access required to execute deliverables. Final models are deployed with strict Row-Level Security (RLS) to enforce internal data governance.

04. Data Processing Agreements

I operate strictly as a Data Processor. Your organization remains the Data Controller. All workflows are governed by a mutual NDA and DPA prior to any infrastructure auditing.