About

I'm Ed Borner, CTO of The DPG (a UK data privacy company) and co-founder of DPG Labs. I've spent twenty years in engineering, most of it as a solutions architect, and these days I spend it connecting privacy platforms like OneTrust and Transcend to the systems businesses actually run on: CRMs, ERPs, and the long tail of software that was never designed with a data subject request in mind.
That work has taken me across finance, airlines, healthcare, and pharma: industries where the rules are strict, the systems are old, and "just export the data" is never as simple as it sounds.
This blog is where I write it down: best practices, architectural approaches, and honest notes from the field on privacy engineering, or PrivTech, if you prefer. It has a technical slant, but privacy is the throughline.
If there's one belief running under most of what I write, it's this: automation is the point. Taking the human out of the loop isn't only how you scale; it's how you make privacy operations standard, repeatable, and trustworthy. A DSR fulfilled by hand is a DSR waiting to go wrong.
No trackers, no popups, no newsletter gate. Just writing. Everything here is my own opinion and, like all opinions, subject to revision.
What I write about
- Integrating privacy platforms (OneTrust, Transcend) with real-world CRMs, ERPs, and data stores
- Making DSR, ROPA, and consent flows work at scale, and automatically
- Architecture and trade-offs for privacy engineering in regulated industries
Elsewhere
If something here was useful, or wrong, I'd like to hear about it.