Privacy by design means building data protection into the technical and organisational design of systems, products and processes from the outset.
Content of the obligation
Controllers must take appropriate measures, both when determining the means of processing and during the processing itself, to implement the data protection principles effectively. The state of the art, the costs, the nature and purpose of the processing and the risks must be taken into account.
Typical measures include pseudonymisation, data minimisation, role and authorisation concepts and automatic deletion routines.
Background
The concept goes back to Ann Cavoukian, the former Information and Privacy Commissioner of the Canadian province of Ontario. The GDPR made it a binding obligation. Manufacturers are not directly bound by it, but according to the recitals they should be encouraged to take data protection into account.
Legal provisions
- Art. 25(1) GDPR
- Data protection by design.
- Recital 78 GDPR
- Explanation of the measures and role of manufacturers.
- Art. 25(3) GDPR
- Certification as an element in demonstrating compliance.