2026-07-20

Research note: blind data-handling (field-proven privacy pattern)

Exploratory principle capture, not build-committed. A pattern the shop actually ran for years.

The pattern

Repair data migration driven by a JOB/TICKET ID, executed blindly:

it rsyncs the customer's data. The tech never sees a filename.

people's private/disturbing/illegal content — a real occupational hazard in repair (techs have found traumatic, legally-radioactive material). Protects BOTH parties.

The principle (same bright line as everywhere else in this engagement)

Handle the data without inspecting it. Password checked locally, never displayed. Breach match by hash, never revealed. Data migrated by ticket ID, never browsed. Sensor analyzed on-device, raw discarded. The sensitive thing is processed by an ID/derived-value; the human (and the log) never sees the content.

Apply to the platform (vetted-technician dispatch)

filenames or content.

outcome) — NEVER filenames or content.

separate, explicitly-consented, separately-authorized, separately-logged step — never the default path, and never silent.

Guardrail

Consent + ownership + WORM + this blind-handling default. Protect the customer AND the worker.

All writing