Taking a privacy by design approach minimises privacy risks and build trust. Designing projects, processes, products or systems with privacy in mind at the outset also enhances culture of proactive data management and improves communication.
While the concept of Privacy by Design is by no means new, it's now an explicit requirement for compliance with the General Data Protection Regulation.
We asked Kate Armitage, Product Quality Assurance Manager and GDPR consultant at Qualsys to share a checklist of requirements for Privacy by Design. A free copy of this Privacy by Design checklist can be downloaded from our GDPR toolkit.
Privacy by Design should happen when making significant changes to systems for use within organisation or by data processors or products and services for the use of individuals or other organisations. For example, when you are building new IT systems for storing or accessing personal data; developing legislation, policy or strategies that have privacy implications; embarking on a data sharing initiative; or using data for new purposes.
For Qualsys, Privacy by Design is a fundamental part of our Change Management Process for all operational and business change. It is an integral part of the Development life-cycle, first being considered at the initial requirements and User Story stage. It is then continued through the development cycle and reviewed by the TD and QA at the Review stage before sign off.
Kate Armitage, Product Quality Assurance Manager at Qualsys
|Key principles of Privacy by Design||Description|
|Proactive not reactive||Anticipate and prevent privacy invasive events before they happen.|
|Privacy as the default||Deliver the maximum degree of privacy by ensuring that personal data are automatically protected in any given IT system or business practice.|
|Privacy is embedded||Privacy is embedded into the design and architecture of IT systems and business practices. It is not bolted on as an add-on. The result is that privacy becomes an essential component of the core functionality being delivered. Privacy is integral to the system, without diminishing functionality.|
|Full functionality||Privacy by Design seeks to accommodate all legitimate interests and objectives in a positive-sum “winwin” manner, not through a dated, zero-sum approach, where unnecessary trade-offs are made. Privacy by Design avoids the pretence of false dichotomies, such as privacy vs. security, demonstrating that it is possible, and far more desirable, to have both.|
|Visibility and transparency||Privacy by Design seeks to assure all stakeholders that whatever the business practice or technology involved, it is in fact, operating according to the stated promises and objectives, subject to independent verification.|
|Respect for users||Keep the interests of the individual uppermost by offering such measures as strong privacy defaults,|
Download the GDPR toolkit: