Privacy by Design (PbD) is an approach to systems engineering that builds privacy into the design of technology and business practices from the outset, rather than adding it as an afterthought. It was developed by Dr. Ann Cavoukian, former Information and Privacy Commissioner of Ontario.
The Seven Foundational Principles
1. Proactive not Reactive; Preventative not Remedial
Anticipate and prevent privacy-invasive events before they happen. Do not wait for a breach to occur before addressing privacy.
2. Privacy as the Default Setting
Personal data should be automatically protected in any given IT system or business practice. No action is required by the individual to protect their privacy — it is built in by default.
3. Privacy Embedded into Design
Privacy is embedded into the design and architecture of IT systems and business practices. It is not bolted on as an add-on after the fact.
4. Full Functionality — Positive-Sum, not Zero-Sum
Privacy by Design accommodates all legitimate interests and objectives in a positive-sum manner. Privacy and security are not in conflict — both can be achieved.
5. End-to-End Security — Full Lifecycle Protection
Privacy by Design extends throughout the entire lifecycle of the data involved, from collection to secure destruction.
6. Visibility and Transparency
All stakeholders can verify that the system operates as promised. Business practices and technologies are visible and transparent.
7. Respect for User Privacy
Above all, Privacy by Design requires architects and operators to keep it user-centric. Offer strong privacy defaults, appropriate notice, and empower users.
Privacy by Design was developed in Ontario and has been recognized internationally. It was adopted as an international standard by the International Assembly of Privacy Commissioners and Data Protection Authorities in 2010.
Learn about Canadian privacy law in PIPEDA Basics.