How to apply Privacy by Design and by Default in the real world
28th October 2024
The General Data Protection Regulation (GDPR) requires organisations to integrate data protection and privacy into all processing activities. This concept, officially designated ‘data protection by design and by default’ is more often referred to as Privacy by Design. Privacy should be implemented into a product or service at each stage and ‘hard baked’ into its design. This improves project development, ensures compliance and can help to avoid any potential data breaches down the line.
Data protection by design and by default helps organisations to align with the seven principles of data protection.
The Data Protection Principles
Article 5 of the UK GDPR describes the seven key principles which make up the foundations of data protection laws in the UK. They are:
1. Lawfulness, fairness and transparency
All data processing must have a lawful basis, all use of personal data must be fair, and organisations must be open and transparent about how personal data will be used from the point of collection.
2. Purpose limitation
Controllers must only collect and process personal data for a specific, well-documented purpose, and not further use it for a different purpose unless they have a different valid lawful basis. The purpose of processing should be stated in a Controller’s public privacy notice.
3. Data minimisation
Organisations must not collect more information than is strictly necessary to achieve the purpose stated above. Any additional data collected that is not needed for the stated purpose should be deleted. For example, an eCommerce store does not need to know a customer’s date of birth unless they are buying age-restricted products like alcohol.
4. Data accuracy
It is an organisation’s responsibility to take all reasonable steps to ensure that the data they collect and process is accurate and not misleading. Where decisions are being made on individuals, Controllers must also keep the personal data updated as time goes by. Individuals have a right to have incorrect or misleading information corrected or erased.
5. Storage limitation
Organisations should not keep data for longer than required to achieve the purpose identified in Principle 2. Controllers should have a data retention policy that details how long they store personal data and have periodic reviews where all held data is erased or anonymised if it is no longer needed. Personal data can be stored for longer if it is for archival, scientific, research or public interest purposes, but it should be anonymised or pseudonymised wherever possible. Other specific rules apply to using data for research purposes.
6. Integrity and confidentiality
All stored data should be appropriately protected using other technical measures, such as encryption, password controls, firewalls etc, and other organisational measures, such as training, policies and accurate record keeping.
7. Accountability
Organisations should take full responsibility for their data processing activities, and make sure they are compliant with the GDPR and other data protection laws. However, it is not sufficient just to be compliant, Controllers must be able to demonstrate compliance. They should therefore have appropriate measures to prove that they took all necessary steps to comply with these principles through records, documentation, audits and oversight framework. Privacy by design is a significant element in the Accountability Principle.
What is data protection by design?
Article 25 (1) of the GDPR states that data controllers should “implement appropriate technical and organisational measures” to ensure privacy by design and protect data subjects’ rights.
When a new processing activity is being considered, or a new product, service, website or other system is designed, it should include features and functionality that ensure all data protection principles are upheld. For example, suppose an organisation is creating an eCommerce website. In that case, the site should be designed so that it only collects the minimum information from users, such as their name, email address, delivery address and payment details during checkout. They should avoid collecting extra data like the user’s date of birth unless legally required. This adheres to the principle of data minimisation.
Any proposed system must be designed with appropriate features that allow a Controller to comply with all other principles, such as storage limitation, i.e. the system must have a way of deleting records when no longer required, and keep accurate audit trails. As per the data protection principle of integrity and confidentiality, personal data collected should be encrypted when transmitted and stored so that if a data breach does happen, customers’ personal data will not be readable.
What is data protection by default?
Article 25 (2) of the GDPR demands data protection by default, saying “by default, only personal data which are necessary for each specific purpose of the processing are processed.”
Data protection by default is directly linked to the second and third principles, i.e. those of purpose limitation and data minimisation. Controllers must only use the data necessary for the purpose. However, data protection by default goes further. It requires Controllers to adopt a privacy-first methodology, for example, turning privacy settings on by default and allowing individuals to turn them off. This may not always be practical and will be reviewed on a case-by-case basis, but when vulnerable people are concerned, privacy settings must be set high.
Data protection by default also reinforces other obligations placed on Controllers, such as the fairness and transparency principle. For example, designing your system to require consent from data subjects and not making assumptions about an individual’s consent to data processing. If a service requires account registration or collects personal data at signup, the website or platform should ask for explicit consent to process a user’s data. Consent boxes should not be pre-ticked, especially when the processing is for marketing purposes as per the Privacy and Electronic Communications Regulations, aka PECR. Users must specifically opt in to receive promotional emails or notifications.
As mentioned, unless there is a valid lawful reason to the contrary, the default privacy settings on an app or platform should also be set to private. If a user wishes to share their content, e.g. on a social media platform, they can change the default settings to friends only or public themselves. Geolocation tagging should also be turned off by default.
Controllers are expected to build best practices into their designs, for example, if a user deletes their account on a platform, then by default, all of their personal data stored on the platform should be deleted permanently. There could be a short retention period, e.g. 30 days in case they reactivate their account, but as per the principle of storage limitation, their data should not be stored for longer than necessary. Users should not have to make a specific request for erasure, or need to make sure their data is deleted after this time – it should occur automatically.
Privacy by design
By Applying the concepts of data protection by design and by default, organisations can ensure the privacy of users and the security of their data is automatically protected. Users won’t be forced into sharing more information than necessary, and they can be confident that their data is protected on multiple levels. This helps organisations stay compliant with the GDPR and also builds trust with users, as it shows they are taking a proactive approach to data protection.
However, there are valid commercial reasons for adopting this practice. By considering all of the risks at the start of the process and specifying what features and functionality your processing system must have at the outset will avoid the need for expensive project changes and system iterations and ensure that a GDPR-compliant system is delivered.
Organisations should therefore consider conducting a Data Protection Impact Assessment (DPIA) before embarking on any new project where personal data will be collected. However, a full DPIA is only recommended for high-risk situations such as collecting special category data or the data of vulnerable individuals such as minors. A DPIA can help to identify potential risks and offer the chance to mitigate them at the conceptual stage.
This proactive approach can reduce the risk of a personal data breach, help to anticipate future events, such as changes in technology and legislation, and for those in the public sector, better manage FOIA requests.
If you need some assistance with creating a DPIA or implementing data privacy by design and by default into a new system, product or service, contact us at Griffin House Consultancy for expert advice.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.