Finding
Regulatory debt
Things stall at review because privacy was left until after the build.
The pattern is always the same: something is built, then shown to legal, then rebuilt. Nobody involved did anything wrong. The audit trail, the access model and the data minimisation were simply not part of the specification, and they cannot be added at the end without touching everything.
It reads as legal being slow. It is not. A reviewer who cannot see who touched what, when, and under which authority has no way to say yes, and saying no is the only responsible answer available to them.
This is the one condition where reading about the fix and having the fix are furthest apart, because the fix is an architecture rather than a checklist.
Measured in months of a feature waiting, not in fines.
The next step
A call, always. The answer depends on which regime you are under and what the reviewer has already refused, and neither of those is in an article.
Find out what this is called →