Privacy By Design Without Trade-Offs

Somebody in a product meeting says the privacy control will cost conversion, and the room starts trading. How much conversion, against how much data. The framing feels responsible. The fourth foundational principle of privacy by design rejects it outright.

The seven privacy by design principles

Ann Cavoukian set out seven foundational principles while serving as Information and Privacy Commissioner of Ontario. The European Data Protection Supervisor reproduces the list in its preliminary opinion on privacy by design. Proactive not reactive, preventative not remedial. Privacy as the default setting. Privacy embedded into design. Full functionality, positive-sum not zero-sum. End-to-end security with full lifecycle protection. Visibility and transparency, keep it open. Respect for user privacy, keep it user-centric.

Six of those describe where privacy work happens or what it protects. The fourth describes an attitude to conflict, which is why it behaves differently in both practice and exam questions.

What positive-sum actually claims

Zero-sum thinking treats privacy and functionality as a fixed quantity to divide. Positive-sum denies the premise. The principle holds that a system can deliver full functionality and privacy together. A design presenting the two as opposed has usually stopped looking for a third option.

The EDPS quotes the second principle at length and the wording repays attention there too. Personal data are protected automatically in any given system or business practice. If an individual does nothing, their privacy still remains intact. No action is required from the individual, because the protection is built in by default.

Where privacy by design became law

Article 25 of the GDPR turned part of privacy by design into an enforceable obligation. The EDPS is careful about the distinction. Privacy by design names the broad concept developed over decades. Data protection by design and by default names the specific legal duties in Article 25.

That difference matters for a technologist. Controllers carry the legal obligation, weighing the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, along with the risks. Privacy by design as a broader principle carries an ethical dimension the statute does not reach.

The gap the EDPS flags

One limitation is worth carrying into any product conversation. Article 25 binds controllers rather than the developers of the products and technology those controllers use. A recital encourages producers to take the right to data protection into account when developing and designing, so that controllers and processors can meet their obligations. Encouragement is not obligation.

A technologist choosing a component inherits whatever design decisions its vendor made. Accountability for those decisions stays local.

Turning privacy by design into requirements

The principles do not implement themselves, and the step candidates underestimate is requirements engineering. A goal such as minimise data has to become something testable. Which fields, collected at which point, retained for how long, visible to which role.

Usability sits alongside that. A privacy control the user cannot find has satisfied a specification and failed a person. Testing whether it works belongs in the same cycle as testing whether it exists. Our piece on LINDDUN threat modelling covers the structured way of finding what needs a control at all. The piece on dark patterns in interfaces shows design choices that break the third principle while appearing to satisfy it.

Privacy by design in the CIPT exam

The Body of Knowledge is the IAPP’s published outline of what each certification exam tests. Domain IV, privacy-enhancing strategies, carries the seven privacy by design principles. Questions there describe a scenario and ask which principle it demonstrates or violates.

Two confusions cost marks. Candidates blur principle two, privacy as the default, with principle three, privacy embedded into design. The first asks what happens when the user does nothing. The second asks where the protection lives. They also read the fourth principle as a licence to balance, when it says the opposite. Our piece on the three privacy engineering objectives covers the NIST vocabulary sitting beside privacy by design in the same exam.

Write the seven out from memory, then take a product you use daily and mark which principles it satisfies. The CIPT Exam Question Masterclass at €195 handles the matching questions once the list is solid.

Similar Posts