Privacy by Design

Also known as: PbD

framework · cybersecurity · organizing-schema

Cavoukian's seven foundational principles for embedding privacy into the design of systems and processes.

Privacy by Design (PbD) was articulated by Ann Cavoukian, then Information and Privacy Commissioner of Ontario, beginning in the 1990s and substantially codified in her 2009 'Privacy by Design: The 7 Foundational Principles.' The framework's central commitment is that privacy must be built into the design and architecture of information systems, business practices, and physical infrastructure from the outset, rather than retrofitted as compliance afterthought. The seven principles: (1) Proactive not Reactive; Preventative not Remedial — anticipate privacy invasion before it occurs; (2) Privacy as the Default Setting — no action required by user to maintain privacy, maximum privacy by default; (3) Privacy Embedded into Design — privacy as essential component of design and architecture, not an add-on; (4) Full Functionality — Positive-Sum, not Zero-Sum — accommodate all legitimate interests, avoid false dichotomies between privacy and security/functionality; (5) End-to-End Security — Full Lifecycle Protection — privacy from data collection through retention and disposal; (6) Visibility and Transparency — Keep it Open — verifiable to all stakeholders; (7) Respect for User Privacy — Keep it User-Centric — empower users with strong privacy defaults, notice, and control. PbD was unanimously adopted as an international standard at the 2010 International Conference of Data Protection and Privacy Commissioners. The framework substantially influenced GDPR's 'data protection by design and by default' principle (Article 25) and similar provisions in other modern privacy laws. Privacy by Design has also drawn substantial methodological critique — the principles are aspirational rather than operationally specific, and translating them into concrete engineering practice has been genuinely difficult, with various subsequent frameworks (LINDDUN, contextual integrity, differential privacy practice) addressing operational gaps.

Originators

Ann Cavoukian (Information and Privacy Commissioner of Ontario, foundational); intellectual antecedents in fair information practice principles (FIPPs) high

Year / Decade

1990s (initial development); 2009 (formal articulation of seven principles); 2010 (international adoption); ongoing influence including GDPR Article 25 (2016) high

Primary sources

Cavoukian, A. (2009). 'Privacy by Design: The 7 Foundational Principles' (Information and Privacy Commissioner of Ontario), Cavoukian, A. & Dixon, M. (2013). 'Privacy and Security by Design: An Enterprise Architecture Approach', GDPR Article 25 (2016), ISO/IEC 27701:2019 (Privacy Information Management System extending ISO 27001/27002) high

Core components

Primary use case

Foundation for privacy-engineering practice in product and system design; reference framework in privacy regulation (GDPR Article 25, similar provisions in CCPA, LGPD, PIPEDA, others); basis for privacy program development; integration with broader cybersecurity and engineering practices; foundation for some commercial privacy-engineering tools and services; pedagogical reference in privacy and information ethics education; influence on emerging AI ethics and responsible-AI frameworks.

Common criticisms

Lineage