Privacy and compliance
Compliance filters
Rules applied during collection or processing to exclude disallowed sources, fields or personal data.
In practice
They enforce policy in the pipeline instead of relying on people to remember it.
Where filters act
A collection workflow can apply rules before fetching a source, while selecting fields and before exporting records. An allowlist can limit permitted sources; a field rule can exclude free-text contact details; a delivery check can quarantine records that do not meet the agreed policy. These controls should have named owners and a recorded purpose.
Example: a product-only feed
A catalogue project may need product identifiers, prices and availability but no reviewer names or seller contact details. A field allowlist limits the output to the agreed schema. Test it against pages that contain both product content and incidental personal information. Keep a record of rejected fields or records without unnecessarily copying the sensitive values into diagnostic logs.
Limits of automated checks
A filter can reduce unwanted collection, but it cannot decide every question about permission, appropriate use or contractual requirements. False positives can remove useful records and false negatives can let unwanted fields through. Review representative samples, version the rules and retest after schema or source changes. Treat filters as one part of a reviewed governance process, not as a certificate that every downstream use is compliant.
Import.io runs rate-aware collection, detects and removes personal data, and works under data processing agreements, with each program’s scope agreed up front.
GDPR and PII at Import.io →