From Privacy by Design to Data Protection by Design: Principles and Practical Implementation
Privacy by Design embeds privacy into products, services, and business practices from the start. Explore its seven foundational principles, how they shaped Data Protection by Design under the GDPR, and practical steps organizations can take to turn privacy principles into everyday practice.
Key Points: (1) Privacy by Design (PbD) means building privacy protections into products, services, systems, and business practices from the beginning, rather than addressing privacy after development. (2) Developed by Ann Cavoukian, PbD is based on seven foundational principles, including proactive protection, privacy by default, lifecycle security, transparency, and user-centric design. (3) Privacy should be embedded into design decisions, including data collection, access, retention, security, interfaces, and third-party integrations. (4) PbD favors positive-sum solutions: privacy does not necessarily have to come at the expense of security, functionality, or legitimate business objectives. (5) Implementation requires more than engineering. Organizations need privacy governance, policies, early privacy-team involvement, assessments, periodic reviews, and third-party oversight. (6) Privacy by Design has influenced modern privacy and data protection regulation worldwide, most notably the GDPR's Data Protection by Design and by Default requirements under Article 25. (7) Privacy by Design and GDPR Data Protection by Design are related but not identical: PbD originated as a privacy framework, while Article 25 creates an enforceable data protection obligation under EU law.
Privacy by Design (PbD) is an approach to developing products, services, systems, business practices, and infrastructure in which privacy considerations are incorporated from the beginning of the design process and throughout the entire lifecycle.
The basic idea is straightforward: organizations should not build a product first and ask how to address privacy shortly before launch—or after a problem occurs. Instead, privacy requirements should influence the choices made about what personal data is collected, how it is used, who can access it, how long it is retained, how it is secured, and what choices and controls are provided to individuals.
Privacy by Design shifts privacy from a compliance checkpoint at the end of development to a consideration that informs product and organizational decisions from the outset.
Importantly, Privacy by Design originated as a privacy framework, rather than as a specific statutory requirement. Its principles have nevertheless had a significant influence on modern privacy and data protection laws and regulatory approaches, including the GDPR's requirements for data protection by design and by default.
Origins of Privacy by Design
Privacy by Design is closely associated with Ann Cavoukian, who developed the concept while serving as the Information and Privacy Commissioner of Ontario, Canada.
An important early articulation appeared in 1995 in work on privacy-enhancing technologies (PETs) developed jointly by the Information and Privacy Commissioner of Ontario, the Dutch Data Protection Authority, and the Netherlands Organization for Applied Scientific Research (TNO).
The approach was subsequently developed into a broader framework built around seven foundational principles. In 2009, the Information and Privacy Commissioner of Ontario published the Privacy by Design: The 7 Foundational Principles framework.
Privacy by Design gained significant international recognition in 2010, when the International Conference of Data Protection and Privacy Commissioners—now known as the Global Privacy Assembly (GPA)—adopted a resolution recognizing Privacy by Design as an essential component of fundamental privacy protection.
The framework helped establish an idea that is now central to privacy engineering and privacy governance: privacy should be designed into technologies and organizational practices rather than added after they have already been developed.
The Seven Foundational Principles of Privacy by Design
The Privacy by Design framework is organized around seven foundational principles.

1. Proactive, Not Reactive; Preventative, Not Remedial
Organizations should anticipate and prevent privacy risks before they materialize, rather than waiting for a privacy incident, complaint, or regulatory investigation before acting.
This principle extends beyond product development. Effective Privacy by Design requires organizations to develop a broader culture in which teams identify privacy risks early and incorporate privacy considerations into planning and decision-making.
In practice, this can mean conducting privacy reviews during product development, identifying potentially problematic data uses before deployment, and involving privacy professionals while important design decisions can still be changed.
2. Privacy as the Default Setting
Privacy protections should apply automatically, without requiring individuals to take additional steps to protect themselves.
A product or service should therefore be designed so that its default configuration provides appropriate privacy protection. Individuals should not have to locate obscure settings, navigate complicated menus, or opt out of unnecessary processing simply to obtain a privacy-protective experience.
This principle has become particularly important in modern debates concerning privacy defaults, consent interfaces, choice architecture, and dark patterns.
3. Privacy Embedded Into Design
Privacy should be an integral component of the system rather than an additional feature attached to it.
This means translating privacy requirements into technical, organizational, and product requirements during the design process. Decisions about system architecture, databases, permissions, retention periods, interfaces, and third-party integrations can all have privacy consequences.
Privacy therefore becomes part of the product's functionality and architecture—not merely something described in a privacy policy.
4. Full Functionality — Positive-Sum, Not Zero-Sum
Privacy by Design rejects the assumption that protecting privacy necessarily requires sacrificing other legitimate objectives.
Organizations should instead seek positive-sum solutions that accommodate multiple interests whenever possible.
For example, privacy and security should not automatically be treated as competing goals. A thoughtfully designed system may improve both. Similarly, organizations should consider whether business objectives can be achieved through less intrusive processing rather than assuming that privacy protection and commercial functionality are inherently incompatible.
The objective is a "win-win" approach rather than unnecessary trade-offs.
5. End-to-End Security — Full Lifecycle Protection
Privacy protections should extend throughout the entire lifecycle of personal information.
Security and privacy safeguards should begin when personal data is collected—or even earlier, when the processing activity is designed—and continue through its use, storage, disclosure, sharing, archiving, and eventual deletion.
This principle emphasizes that organizations should consider the full lifecycle of information rather than focusing exclusively on securing stored data.
It also means planning for the end of that lifecycle. Personal information that is no longer needed should be securely deleted or otherwise appropriately disposed of.
6. Visibility and Transparency — Keep It Open
Organizations should ensure that their practices and technologies operate in accordance with their stated purposes and can be appropriately scrutinized.
Individuals should be able to understand what personal information is being processed, why it is being processed, and how the organization handles it.
Transparency also supports accountability. Organizations should be able to demonstrate that their systems and practices actually operate as represented rather than asking individuals or regulators simply to trust that appropriate safeguards exist.
7. Respect for User Privacy — Keep It User-Centric
Privacy by Design ultimately places the individual at the center of the design process.
Organizations should consider the interests and expectations of individuals when designing products and services. This can include providing meaningful notices, understandable choices, appropriate controls, privacy-protective defaults, and interfaces that make privacy choices accessible rather than unnecessarily difficult.
The broader objective is to design systems around people rather than expecting people to continually adapt their behavior to compensate for privacy-invasive systems.
How Can Organizations Implement Privacy by Design?
Privacy by Design is more than a set of abstract principles. Organizations need processes that translate those principles into concrete product and operational decisions.
A useful starting point is establishing clear internal privacy and data protection policies. Those policies provide the foundation from which product, engineering, legal, security, and operational teams can identify privacy requirements and determine the safeguards that should be incorporated into systems and business processes.
Organizations should also assign clear responsibility for privacy governance. Depending on the organization and applicable law, this responsibility may sit with a privacy office, legal or compliance team, Data Protection Officer (DPO), Chief Privacy Officer, or another designated function.
The important point is not simply that someone has responsibility for privacy, but that the relevant privacy professionals are involved early enough to meaningfully influence design decisions. A privacy review performed after a product has effectively been completed provides far fewer opportunities to change its architecture or data practices.
Privacy reviews should therefore be integrated into the organization's product development lifecycle. Depending on the processing involved, this may include data inventories, privacy impact assessments (PIAs), data protection impact assessments (DPIAs), security reviews, data minimization assessments, retention reviews, and reviews of notices and user interfaces.
Organizations should also periodically reassess existing products and services. Privacy by Design is a lifecycle process, not a one-time exercise completed at launch. Products evolve, new features are introduced, datasets are combined, vendors change, and new uses of existing information emerge.
Do Not Forget Third Parties
Third-party technologies deserve particular attention.
Integrating a third-party service does not eliminate the privacy consequences associated with that technology. For example, adding an SDK, analytics tool, advertising technology, tracking technology, AI service, API, or other third-party component may result in additional collection or disclosure of personal information.
Organizations should therefore evaluate third-party technologies before deployment and understand, among other things:
- what personal data the third party receives;
- what information the technology automatically collects;
- the purposes for which the third party may use that information;
- whether the information is shared with additional parties;
- applicable retention practices;
- available configuration and privacy controls; and
- whether the integration is consistent with the organization's privacy representations and legal obligations.
Privacy by Design extends beyond what an organization develops itself to the entire technological ecosystem incorporated into its products and services.
Privacy by Design Is Not Just About Engineering
Although Privacy by Design is frequently discussed in connection with software engineering, its scope is considerably broader.
The framework applies to information technologies, organizational practices, business processes, physical design, and networked infrastructure. Marketing practices, customer-service processes, employee systems, vendor relationships, physical access systems, and internal data-governance practices can therefore raise Privacy by Design considerations just as readily as software architecture.
This broader perspective is important because many privacy problems are not caused by a single technical failure. They result from the interaction between technology, business incentives, organizational processes, policies, and human decision-making.
Privacy by Design asks organizations to address privacy across information technologies, organizational practices, business processes, physical design, and networked infrastructure.
From Privacy by Design to Data Protection by Design
Privacy by Design began as a framework rather than a legal rule, but its influence can now be seen in privacy and data protection laws around the world.
The most prominent example is the European Union's General Data Protection Regulation (GDPR). Article 25 requires controllers to implement "data protection by design and by default."
The terminology matters. The GDPR regulates data protection, which is related to but distinct from privacy. Accordingly, Article 25 should not simply be treated as a statutory restatement of Cavoukian's Privacy by Design framework. It places design and default obligations within the GDPR's broader system of data protection principles, individual rights, controller accountability, and regulatory enforcement.
Nevertheless, the connection is important. Both approaches reflect the same fundamental shift in thinking: protecting individuals should be part of how systems are designed, not merely how organizations respond after those systems create problems.
Additional Resources
For readers interested in exploring Privacy by Design (PbD) and Data Protection by Design and by Default in greater depth, the following regulatory guidance, standards, and technical resources provide useful starting points.
Privacy by Design — Foundational Resources: The Information and Privacy Commissioner of Ontario (IPC) played a central role in the development of Privacy by Design under former Commissioner Ann Cavoukian. Key resources include:
- Privacy By Design Primer (Revised 2013)
- Operationalizing Privacy by Design: A Guide to Implementing Strong Privacy Practices (2012) — Ann Cavoukian's practical guidance for translating Privacy by Design principles into organizational practices.
European Union and European Regulators: European regulators have developed extensive guidance on Data Protection by Design and by Default, particularly in connection with Article 25 GDPR.
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default — European Data Protection Board (EDPB). The EDPB's principal guidance on interpreting and applying Article 25 GDPR, including the concepts of effectiveness, appropriate technical and organizational measures, and data protection by default.
- A Guide to Privacy by Design (2019) — Spanish Data Protection Agency (AEPD). Practical guidance on incorporating privacy and data protection requirements into the design of products and services.
- Data Protection by Design and by Default — UK Information Commissioner's Office (ICO). Guidance explaining how organizations can implement data protection by design and default under the UK GDPR.
ENISA — Privacy Engineering and Privacy-Enhancing Technologies: The European Union Agency for Cybersecurity (ENISA) has published research examining how Privacy by Design and Data Protection by Design can be translated into technical measures and engineering practices.
- Privacy and Data Protection by Design — From Policy to Engineering — Explores how legal and policy principles can be translated into concrete engineering requirements and technical mechanisms.
- Privacy by Design in Big Data — Examines privacy engineering and data protection challenges associated with big-data systems.
United States — Federal Trade Commission: Although U.S. law does not contain a general federal equivalent of Article 25 GDPR, the Federal Trade Commission (FTC) has long encouraged businesses to incorporate privacy protections into the development of products and services.
- Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers (2012) — See particularly pp. 22–34, where the FTC discusses Privacy by Design as part of its proposed framework for protecting consumer privacy.
Singapore: The Personal Data Protection Commission (PDPC) of Singapore has developed practical guidance addressing the incorporation of data protection requirements into information and communications technology systems.
- Guide to Data Protection by Design for ICT Systems — Personal Data Protection Commission (PDPC), Singapore. Provides practical guidance for organizations seeking to incorporate data protection principles into the design and development of ICT systems.
International Standards: Privacy by Design principles have also influenced the development of international technical standards.
- ISO - Consumer protection — Privacy by design for consumer goods and services — Work originally undertaken through ISO/PC 317 to develop international guidance for incorporating privacy considerations into the design of consumer products and services. This work resulted in ISO 31700, the international Privacy by Design standard for consumer goods and services.
Differential Privacy and Privacy-Enhancing Technologies: Privacy by Design can also be implemented through privacy-enhancing technologies (PETs) and technical approaches designed to reduce the privacy risks associated with processing data. One increasingly important example is differential privacy, which can allow organizations to derive statistical insights from datasets while limiting what can be learned about particular individuals.
- Implementing Differential Privacy: Seven Lessons From the 2020 United States Census — Michael B. Hawes, Harvard Data Science Review (2020). Examines practical lessons from the U.S. Census Bureau's implementation of differential privacy in connection with the 2020 Census.
