Privacy by Design (PbD) is an approach to systems engineering that builds privacy into the design of technology and business practices from the outset, rather than adding it as an afterthought. It was developed by Dr. Ann Cavoukian, former Information and Privacy Commissioner of Ontario.

The Seven Foundational Principles

1. Proactive not Reactive; Preventative not Remedial

Anticipate and prevent privacy-invasive events before they happen. Do not wait for a breach to occur before addressing privacy.

2. Privacy as the Default Setting

Personal data should be automatically protected in any given IT system or business practice. No action is required by the individual to protect their privacy — it is built in by default.

3. Privacy Embedded into Design

Privacy is embedded into the design and architecture of IT systems and business practices. It is not bolted on as an add-on after the fact.

4. Full Functionality — Positive-Sum, not Zero-Sum

Privacy by Design accommodates all legitimate interests and objectives in a positive-sum manner. Privacy and security are not in conflict — both can be achieved.

5. End-to-End Security — Full Lifecycle Protection

Privacy by Design extends throughout the entire lifecycle of the data involved, from collection to secure destruction.

6. Visibility and Transparency

All stakeholders can verify that the system operates as promised. Business practices and technologies are visible and transparent.

7. Respect for User Privacy

Above all, Privacy by Design requires architects and operators to keep it user-centric. Offer strong privacy defaults, appropriate notice, and empower users.

Canadian Origin

Privacy by Design was developed in Ontario and has been recognized internationally. It was adopted as an international standard by the International Assembly of Privacy Commissioners and Data Protection Authorities in 2010.

Next Step

Learn about Canadian privacy law in PIPEDA Basics.

← Retention PIPEDA Basics →