

Using privacy by design to bake privacy in early is becoming a must. The benefits of using privacy by design to ensure privacy in the early stages of development of products and services range from better alignment with organisational priorities to happier customers. Plus it supports compliance in an increasingly complex world of data protection regulation.
However, many organisations don’t know where to start. We are here to help. In this post we outline three steps that are key to implementing privacy by design at your organisation:
Privacy has evolved from a compliance checklist item to an opportunity for organisations to:
If your organisation’s approach to privacy doesn’t reflect this reality, it’s time to change the narrative about privacy.
How do you do this? One way is to create a vision for privacy within the organisation. This vision must be linked to your strategic direction and show how supporting privacy brings value to your business. This might be by supporting the fair and ethical leveraging of the data you hold or building and maintaining stakeholder trust. Whatever the value statement, it’s an important starting point for any privacy by design program.
From the outset, you need to consider how your systems and processes operate independently and together and create an action plan for privacy that adequately reflects the risks that arise, while supporting your organisational vision for privacy.
The Privacy by Design framework states that privacy should be the default – and that a person who does nothing to protect their privacy should still be protected. It’s crucial to bear this in mind when you develop your systems.
To achieve this, consider:
Human error remains one of the leading contributors to privacy breaches. It’s important to consider how humans will interact with your systems.Where might things go wrong? What decisions about data use might be presented in the future? And remember to think about all the human points of contact – employees, customers, website visitors, partners and third parties in the supply chain. Privacy by design needs to cover all interactions with personal data,
From there, you need to develop processes that strengthen (not weaken) your systems and technical security measures.
Regarding your processes, it’s essential to:
Your legal compliance obligations will vary depending on which jurisdictions you operate within. Broadly speaking, compliance often centres around the following common themes:
Compliance should not be the main driver for Privacy by Design but it is an important input.
It’s not enough for your organisation’s privacy professionals to know and understand privacy. Your whoke team must be trained to know and recognise privacy risks, too.
Privacy by design requires that privacy is baked into everything from marketing to customer service. As a result, all team members should receive privacy training. This training should be directed to the different team members who might be involved in the privacy by design process, and what is important for them to know. For example, it might include:
Privacy training is a good practice in any event. Privacy risks are developing rapidly, and ongoing training is critical to reducing your organisational risk.
Here are some other resources that might help:
For other tips on embedding privacy by design into your organisational practices, check out some of our other posts:
Privacy by Design: A Future-Focused Privacy Approach for Your Organisation
If you need assistance with privacy at your organisation, reach out. Our team of privacy lawyers, training instructors, and consultants would love to help.
Alternatively, to learn more about how to build privacy in your business and your technology solutions, enrol in our CIPT Course.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.