Terravek ran a GDPR programme through 2017 and 2018 like everybody else. Records of processing, DPIAs, a privacy notice nobody read, an appointed DPO. Five years on, the parts that mattered are not the parts we expected.

What mattered least: the documentation. It is necessary and it is not transformative. A record of processing activities is a filing system.

What mattered most: the discipline of having to name a lawful basis before starting to process something. That question — why are we allowed to have this — turns out to be a good general-purpose design constraint, and it has killed several product ideas early and cheaply.

The second thing that mattered: data minimisation as an engineering default. Terravek holds a lot of imagery of the Earth's surface. Very little of it needs to be linked to a person, and the discipline of asking whether a given field needs to exist has measurably reduced what we store.

Earth observation raises privacy questions that the GDPR does not answer cleanly — resolution thresholds, inference about individuals from land use, aggregation. We have a written position on each and it is reviewed annually. It is on the privacy page.