Privacy by design moves decisions earlier
The cheapest moment to decide what you will not collect is before anything is built.
After launch, the data model is fixed, other systems depend on it, users have expectations and changing the default is a migration. Before, it is a conversation. The principle is not really about privacy features; it is about when the decisions get made, because by the time it is a retrofit the answer is usually no.
More on Privacy engineering
- Anonymisation is about re-identification riskThe name was the easy part
- Differential privacy limits one person's influenceOne person cannot move the needle
- Consent interfaces can undermine genuine choiceBoth answers, very different distances
- Purpose limitation prevents silent mission creepThe pipe was laid for one thing
- A privacy notice does not create permissionTelling is not asking
- Data subject rights depend on finding the dataThe right ends where the index does
