Privacy by Design is an approach that promotes privacy and security through design decisions at every stage of product development. It requires proactive consideration of privacy to minimize risks.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Privacy by design embeds privacy requirements from the outset in product decisions, processes, and technical architectures.
Ann Cavoukian formulated the approach as a proactive design principle; Article 25 of the GDPR established data protection by design and by default as a legal requirement.
Treat privacy as a system requirement: identify data flows and risks early, minimise collection and access, set protective defaults, and check effects throughout the lifecycle. Document decisions and give affected people understandable control.
Only data necessary for the defined purpose is collected and processed.
The default configuration protects privacy without requiring user action first.
A structured assessment of processing risks to people and planned mitigations.
Privacy by design moves privacy into the design process and reduces later rework and surprises. It requires interdisciplinary ownership, verifiable controls, and reassessment as systems change.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.