Privacy by design

Privacy built into a system while it is being designed is achievable. Privacy added afterwards is expensive, partial and often impossible.

By the time something is live, the data model has been decided, the collection is happening, other systems depend on it and the defaults have set expectations. Changing any of that is a project. Deciding at the start what you will not collect, how long you will keep it and what the default setting is costs almost nothing, because nothing has been built yet.

Checked against the primary source.

More on Data protection & privacy