Privacy by Design
Also known as: PbD
Cavoukian's seven foundational principles for embedding privacy into the design of systems and processes.
Privacy by Design (PbD) was articulated by Ann Cavoukian, then Information and Privacy Commissioner of Ontario, beginning in the 1990s and substantially codified in her 2009 'Privacy by Design: The 7 Foundational Principles.' The framework's central commitment is that privacy must be built into the design and architecture of information systems, business practices, and physical infrastructure from the outset, rather than retrofitted as compliance afterthought. The seven principles: (1) Proactive not Reactive; Preventative not Remedial — anticipate privacy invasion before it occurs; (2) Privacy as the Default Setting — no action required by user to maintain privacy, maximum privacy by default; (3) Privacy Embedded into Design — privacy as essential component of design and architecture, not an add-on; (4) Full Functionality — Positive-Sum, not Zero-Sum — accommodate all legitimate interests, avoid false dichotomies between privacy and security/functionality; (5) End-to-End Security — Full Lifecycle Protection — privacy from data collection through retention and disposal; (6) Visibility and Transparency — Keep it Open — verifiable to all stakeholders; (7) Respect for User Privacy — Keep it User-Centric — empower users with strong privacy defaults, notice, and control. PbD was unanimously adopted as an international standard at the 2010 International Conference of Data Protection and Privacy Commissioners. The framework substantially influenced GDPR's 'data protection by design and by default' principle (Article 25) and similar provisions in other modern privacy laws. Privacy by Design has also drawn substantial methodological critique — the principles are aspirational rather than operationally specific, and translating them into concrete engineering practice has been genuinely difficult, with various subsequent frameworks (LINDDUN, contextual integrity, differential privacy practice) addressing operational gaps.
Core components
- Seven foundational principles: Proactive not Reactive, Privacy as Default, Privacy Embedded into Design, Full Functionality (positive-sum), End-to-End Security, Visibility and Transparency, Respect for User Privacy
- Connection to fair information practice principles (FIPPs)
- GDPR Article 25 'data protection by design and by default'
- Application to systems, business practices, physical infrastructure
- Distinction from compliance-driven privacy
- Aspirational rather than operationally specific
- Subsequent operational frameworks (LINDDUN threat modeling, differential privacy, contextual integrity) addressing engineering gaps
Primary use case
Foundation for privacy-engineering practice in product and system design; reference framework in privacy regulation (GDPR Article 25, similar provisions in CCPA, LGPD, PIPEDA, others); basis for privacy program development; integration with broader cybersecurity and engineering practices; foundation for some commercial privacy-engineering tools and services; pedagogical reference in privacy and information ethics education; influence on emerging AI ethics and responsible-AI frameworks.
Common criticisms
- Principles are aspirational rather than operationally specific — translating 'privacy embedded into design' or 'privacy as default' into concrete engineering decisions is genuinely difficult, with substantial gap between principle and practice
- commercial 'Privacy by Design' implementations vary substantially in fidelity and operational depth
- the 'positive-sum' principle (full functionality without privacy tradeoffs) has been criticized as wishful thinking — real engineering decisions often involve genuine tradeoffs that the principle obscures
- subsequent operational frameworks (LINDDUN, differential privacy, contextual integrity) address gaps that PbD's high-level framing leaves unsolved
- commercial privacy consulting industry has produced compliance-style PbD applications with limited substantive engineering change
- Cavoukian herself has criticized GDPR's implementation of the principles as inadequate to the original vision
- integration with agile and DevOps practices has been incomplete — privacy-by-design at the start of design doesn't address ongoing change
- tension between the principles' user-centric framing and the actual asymmetric power between data controllers and data subjects in many contexts
- some critics argue PbD has been more rhetorical than operational in many high-profile applications.