Safeguarding Privacy through Data Protection by Design and by Default

19th March 2024

Data protection by design and by default, formally known as privacy by design, is a concept that has been gaining traction in the area of privacy and cyber security. With the increasing digitisation of services and products, ensuring the confidentiality and security of user data has become paramount. This concept is not a new one as it has always been part of UK data protection laws. 

Data protection by design and by default is a fundamental project methodology within data protection legislation and especially the UK General Data Protection Regulation (UK GDPR) that requires a risk assessment of all data protection and processing activities to be performed at the conception and design stage of a project and throughout the entire lifecycle. This obligation is outlined in Article 25 of the UK GDPR, emphasising the need for organisations to consider privacy, confidentiality and data protection issues as an integral part of the design and implementation of systems, services, products, and business practices.

In simple terms, before you commence with a new data processing activity you have to consider the potential data protection and cyber security risks associated with the processing activity at the concept stage, and at the very latest BEFORE any processing of personal data takes place.  

What is the difference between design and default in data protection?

Data protection by design is a practice that ensures that confidentiality and data protection concerns are addressed during the design phase of any system, service, product, or process, as well as throughout its life cycle. On the other hand, data protection by default requires a Controller to hard-bake data protection and elements to protect the privacy of data subjects in every policy and procedure. It requires Controllers to embed the core data protection principles into all data processing activities.

Best Practices for Data Protection

The guidance notes in Article 25 provided by the ICO can help organisations in developing a culture of privacy awareness. 

Proactive not reactive, preventative not correction

These wise words were taken directly from ICO guidance and sum up Privacy By concepts. Systems, services, products, and business practices should be designed to automatically safeguard personal data. Protecting privacy and confidentiality should be inherent in every system processing personal data, ensuring that individuals’ data remains protected without requiring any action on their part. This approach guarantees that confidentiality is preserved effortlessly by the user.

Privacy built into design

Data protection should be seamlessly integrated into the architecture of systems, services, products, and business operations. This integration means that data protection is not an add-on but a fundamental component of the system or service, embedded within its essential functions.

Achieving comprehensive functionality – Positive-sum approach

This principle, often described as creating a ‘win-win’ situation, emphasises the importance of not compromising one objective for another, such as trading confidentiality for security. Instead, the aim is to fulfil all legitimate goals while adhering to data protection obligations, demonstrating that it is possible to respect the privacy of data subjects and protect the confidentiality of their information alongside other objectives.

Lifelong security measures

Controllers should implement robust security protocols right from the start and maintain these protections throughout the entire data lifecycle. This means processing data securely from collection to destruction, ensuring data is protected at every stage.

Openness and clarity – Ensuring transparency

It’s crucial that the technologies and business practices used in processing personal data, their purpose and operations can be independently verified. Transparency also involves making sure individuals are fully aware of what data is being processed, why it is being processed, and ensuring this process is open to scrutiny. Invisible processing, which refers to processing operations which take place without the knowledge of the data subject (unless you are involved in national security or crime detection), is very rarely lawful.

Prioritising user privacy – user-centric approach

Place the privacy and interests of users at the forefront when designing and implementing any system or service. This includes offering robust privacy settings by default, giving users control over their data, and providing clear notices. This user-centric approach ensures that respect for user privacy is a key consideration in system and service design.

The Accountability Framework

Accountability is one of the key principles in data protection law and simply makes Controllers responsible for complying with data protection legislation.

The Accountability Principle simply means that a Controller must not only be compliant with data protection legislation but also be able to demonstrate their compliance.

The Accountability framework provides a structure or ‘framework’ which Controllers can follow to meet their accountability obligations. The ICO has provided detailed guidance and tools to help organisations meet their data protection by design and by default obligations. 

The accountability framework both informs and helps to reinforce the data protection compliance messages outlined in organisational policies and procedures. These policies and standard operating procedures provide clarity and consistency by communicating what actions people in an organisation need to take, at what time and why. It also helps to communicate goals and values in an accessible way.

To meet the expectations of the ICO in terms of policies and procedures that foster data protection by design and by default across an organisation, the following should be put in place:

  • Personal data of vulnerable groups such as children are given extra protection in policies and procedures.
  • Policies and procedures are designed in such a way that personal data is always protected.
  • An organisation’s approach to implementing data protection principles and safeguarding human rights is set out in policies and principles.

You must ensure data protection by design and by default is hard baked into organisational systems and that they cannot be bypassed

Data protection by design and by default is a fundamental and mandatory concept that underscores the UK GDPR’s approach to confidentiality, privacy and data protection. By following the ICO’s guidelines, organisations can ensure that they not only comply with legal requirements but also foster trust and confidence among their users and customers. Implementing this principle effectively requires a commitment to embedding data protection into the DNA of an organisation’s culture and operations, thereby safeguarding individuals’ rights. 

For more information on Data Protection by design and by default, see the following resources, or just call the Griffin House Consultancy and we will help you implement the framework in a pain and hassle-free way: 

Data protection by design and default

The Accountability Framework

Policies and procedures

 

Author: Paul Adams LLB (HONS)

Paul is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details