Implementing a by design and by default approach
Richard Preece — Journal of Data Protection Privacy
Richard Preece — Journal of Data Protection Privacy
How it connects
Related across sources
Full text
Building upon the concept of privacy by design, security and data protection by design and by default are important obligations within the General Data Protection Regulation (GDPR) and associated national legislation. This paper seeks to summarise some practical approaches to develop effective capability to deliver by design requirements: (1) a whole project lifecycle design approach; (2) a contextual riskbased approach; (3) the use of goals and principles approach; and (4) integration of safeguards/controls into operational use. While by default requires: (1) only processing that is necessary approach; and (2) not releasing data to unauthorised people.