{"id":1479,"date":"2018-08-31T11:52:29","date_gmt":"2018-08-31T09:52:29","guid":{"rendered":"https:\/\/staging.techgdpr.com\/?p=1479"},"modified":"2024-02-22T18:09:43","modified_gmt":"2024-02-22T17:09:43","slug":"what-the-gdprs-privacy-by-design-really-means-for-your-business","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/","title":{"rendered":"What the GDPR&#8217;s &#8216;Privacy By Design&#8217; Really Means for Your Business"},"content":{"rendered":"\n<p><span style=\"font-weight: 400;\">How, exactly, can privacy be <em>designed?&nbsp;<\/em>Companies concerned about Europe&#8217;s&nbsp;<\/span><a href=\"http:\/\/www.eugdpr.org\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">General Data Protection Regulation<\/span><\/a><span style=\"font-weight: 400;\"> (GDPR) may or may not have already considered the curious concept of &#8220;privacy by design and privacy by default&#8221; \u2014 but consider it, they must. While it&#8217;s hardly the most charming regulatory text ever written, it&#8217;s implications are vast, and understanding it properly saves startups considerable time and money (and headaches) if they begin implementing a few key privacy procedures while they are still at earlier stages of product and procedural development.&nbsp;<\/span><span style=\"font-weight: 400;\">The legal nuts and bolts can be found in&nbsp;<\/span><a href=\"https:\/\/gdpr-info.eu\/art-25-gdpr\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Article 25<\/span><\/a><span style=\"font-weight: 400;\"> of the GDPR, with this excerpt below clarifying the main requirements:&nbsp;<\/span><\/p>\n\n\n\n<p><em><span style=\"font-weight: 400;\">\u201cIn order to be able to demonstrate compliance with this Regulation, the controller should adopt internal policies and implement measures which meet in particular the principles of data protection by design and data protection by default. Such measures could consist, inter alia, of minimizing the processing of personal data, pseudonymising personal data as soon as possible, transparency with regard to the functions and processing of personal data, enabling the data subject to monitor the data processing, enabling the controller to create and improve security features.\u201d (<\/span><a href=\"https:\/\/www.privacy-regulation.eu\/en\/r78.htm\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Recital 78<\/span><\/a><span style=\"font-weight: 400;\">)<\/span><\/em><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Simply put, the GDPR <\/span><a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/reform\/rules-business-and-organisations\/obligations\/what-does-data-protection-design-and-default-mean_en\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">expects <\/span><\/a><span style=\"font-weight: 400;\">companies and other organizations to implement technical and organizational measures at their earliest stages of design and at the earliest stages of their operations.&nbsp; They need to do this in a way that safeguards privacy and data protection principles right from the start (&#8220;data protection by design&#8221;). Such requirements are also, quite frankly, simple due diligence in the world of reliable data management. So, how does one actually &#8220;design&#8221; data protection for data subjects?<\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><b>What is Privacy by Design?<\/b><\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">Privacy by design is not a new concept. It is the <\/span><span style=\"font-weight: 400;\">philosophy<\/span><span style=\"font-weight: 400;\"> proposed by <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Ann_Cavoukian\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Dr. Ann Cavoukian<\/span><\/a><span style=\"font-weight: 400;\">, the Information and Privacy Commissioner of Ontario in the 1990s. Ann Cavoukian is widely recognized as the primary creator of the privacy by design concept. She defines it as an <\/span><a href=\"http:\/\/gpsbydesign.org\/\"><span style=\"font-weight: 400;\">approach<\/span><\/a><span style=\"font-weight: 400;\"> to technology design that embeds privacy-enhancing measures into technology at the point of design and production, and sells to technology to consumers with strong default privacy settings. The foundational principles of \u201cPrivacy by Design\u201d as suggested by Ann Cavoukian are:<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><span style=\"font-weight: 400;\">Privacy by design is proactive, not reactive; it is preventative, not remedial. Privacy by design anticipates and protects privacy against negative and invasive effects of new products and technologies before they happen.<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">Privacy by design ensures privacy as the default, which means that personal data are automatically protected in any given IT system. If an individual does nothing, their privacy still remains intact. <strong><em>No action is required on the part of the individual to protect their privacy \u2212 it is built into the system, by default.<\/em><\/strong><\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">Privacy by design means that privacy is embedded into the design and the architecture of the IT system. It is not bolted on, after-the-fact. The result is that privacy becomes an essential component of the core functionality that is being delivered.<\/span><\/li>\n<\/ul>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-67-1024x439.png\" alt=\"\"\/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><span style=\"font-weight: 400;\">Privacy by design permits full functionality. When embedding privacy into a given technology, process, or system, it should be done in such a way that full functionality is not impaired, and to the greatest extent possible, that all requirements are optimized.<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">Privacy by design extends securely throughout the entire lifecycle of the data involved. Strong security measures are essential to privacy, from start to finish. Privacy must be continuously protected across the entire domain and throughout the life-cycle of the data in question. There should be no gaps in either protection or accountability. The \u201cSecurity\u201d principle has special relevance here because, at its essence, without strong security, there can be no privacy.<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">Privacy by design seeks to assure visibility and transparency, as they are essential to establishing accountability and trust.<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">Privacy by design is consciously designed around the interests and needs of individual users, who have the greatest vested interest in the management of their own personal data. The architects should keep the interests of the individual uppermost by offering such measures as strong privacy defaults, appropriate notice, and empowering user-friendly options. Keep it user-centric!<\/span><\/li>\n<\/ul>\n\n\n\n<p><span style=\"font-weight: 400;\">After the GDPR came into force on May 25th, 2018 many companies became tempted to regard the regulation as a compliance burden. However, GDPR is about reputation and not just regulation. The benefits of meeting the requirement for data protection by design, which is essentially the GDPR\u2019s version of \u201cprivacy by design\u201d go far beyond any legal compliance.&nbsp; Also, as stated earlier, much of it is standard housekeeping&nbsp;if you are already a company that prioritizes data security.&nbsp;<\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>New Consumer Privacy Expectations<\/strong><\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">Studies have shown that data privacy is a consideration steadily more expected by the consumers. According to a<\/span><span style=\"font-weight: 400;\"> survey<\/span><span style=\"font-weight: 400;\"> conducted online by The Harris Poll on behalf of IBM between March 20-26th, 2018, 78% of U.S. respondents say that a company&#8217;s ability to keep their data private is &#8220;extremely important&#8221; and only 20% &#8220;completely trust&#8221; organizations they interact with to maintain the privacy of their data. This suggests that privacy breaches not only have significant financial implications but can also cause reputational damage.&nbsp; If consumers do not feel that their privacy is being protected, they will seek out <a href=\"https:\/\/coincentral.com\/blockchain-digital-advertising\/\" target=\"_blank\" rel=\"noopener\">other means<\/a> of ensuring their privacy.&nbsp;<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Embracing privacy from the design phase enables companies to protect customers\u2019 data and enhance their business reputation. It enables trusted, long-term relationships with the existing customers and the opportunity to attract new ones. Irrespective of whether they are affected by the regulatory framework itself, companies should make privacy an integral part of their DNA and their offering for their existence and for their customers\u2019 well being. <\/span><span style=\"font-weight: 400;\">This is good news for those working in any sector, including IoT (Internet of Things), machine learning, and blockchain. <\/span><\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-68-2-1024x439.png\" alt=\"\"\/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">The reality\u2014that brand reputation and consumer trust are inextricably linked\u2014is especially true in the IoT context. According to one <\/span><a href=\"https:\/\/www.businesswire.com\/news\/home\/20180612005154\/en\/Juniper-Research-IoT-Connections-Grow-140-Hit\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">estimate<\/span><\/a><span style=\"font-weight: 400;\">, the total number of connected IoT sensors and devices is set to exceed 50 billion by 2022, up from an estimated 21 billion in 2018. Consumers (or as the GDPR calls them, &#8220;data subjects&#8221;) want organizations to give them more control over their personal information as the Internet of Things (IoT) grows, and connected devices harvest even more of their data, according to\u00a0<\/span><a href=\"https:\/\/internetofbusiness.com\/consumers-demand-more-data-privacy-from-the-iot-economist-report\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">research<\/span><\/a><span style=\"font-weight: 400;\"> from the Economic Intelligence Unit (EIU). As more devices, platforms, and infrastructure connect to the Internet in real-time, the most successful industry participants will be those that regard Privacy by Design as an opportunity to demonstrate that they are worthy of consumers\u2019 trust. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">A recent <\/span><span style=\"font-weight: 400;\">report<\/span><span style=\"font-weight: 400;\"> by O&#8217;Reilly outlines the current state of machine learning adoption in the enterprise and reveals that in order to keep pace with developing privacy needs, machine learning needs to evolve. \u201cWith the EU&#8217;s recent General Data Protection Regulation mandates, more companies will begin to implement privacy safeguards into their machine learning practices\u201d, says the report. It further reveals that the GDPR pushes for &#8220;privacy by design,&#8221; and that more businesses are taking interest in privacy-preserving analytic methods. These methods include techniques like differential privacy, homomorphic encryption, federated learning, and more. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Such privacy-preserving applications not only help companies become GDPR complaint but also allow users to benefit from the security of <a href=\"https:\/\/techgdpr.com\/blog\/bittersweet-relationship-blockchain-gdpr\/\" target=\"_blank\" rel=\"noopener\">blockchain<\/a>, among other technologies.&nbsp; It&#8217;s worth noting that the popularity of new&nbsp;<a href=\"https:\/\/www.mintdice.com\/blog\/eos-blockchain-to-take-over\" target=\"_blank\" rel=\"noopener\">decentralized networks<\/a> comes in large part from the expectation that they offer a means of protecting one&#8217;s identity. Ultimately, whatever the technology, taking early action to preserve personal privacy is a winner for both the parties, the companies and the users.&nbsp; The sooner you start, the easier it will be.&nbsp;<\/span><\/p>\n\n\n\n<p>For more insights, follow <strong><a href=\"https:\/\/twitter.com\/techgdpr\" target=\"_blank\" rel=\"noopener\">TechGDPR on Twitter.<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How, exactly, can privacy be designed?&nbsp;Companies concerned about Europe&#8217;s&nbsp;General Data Protection Regulation (GDPR) may or may not have already considered the curious concept of &#8220;privacy by design and privacy by default&#8221; \u2014 but consider it, they must. While it&#8217;s hardly the most charming regulatory text ever written, it&#8217;s implications are vast, and understanding it properly [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":1486,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[11,6,7],"tags":[],"class_list":["post-1479","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-subjects","category-iot","category-privacy-by-design"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png",1408,604,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1-300x129.png",300,129,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1-768x329.png",640,274,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1-1024x439.png",640,274,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png",1408,604,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png",1408,604,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png",200,86,false]},"post_excerpt_stackable":"<p>How, exactly, can privacy be designed?&nbsp;Companies concerned about Europe&#8217;s&nbsp;General Data Protection Regulation (GDPR) may or may not have already considered the curious concept of &#8220;privacy by design and privacy by default&#8221; \u2014 but consider it, they must. While it&#8217;s hardly the most charming regulatory text ever written, it&#8217;s implications are vast, and understanding it properly saves startups considerable time and money (and headaches) if they begin implementing a few key privacy procedures while they are still at earlier stages of product and procedural development.&nbsp;The legal nuts and bolts can be found in&nbsp;Article 25 of the GDPR, with this excerpt below&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-subjects\/\" rel=\"category tag\">Data Subjects<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/iot\/\" rel=\"category tag\">IoT<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/privacy-by-design\/\" rel=\"category tag\">Privacy by Design<\/a>","author_info":{"name":"Anamike Ved","url":"https:\/\/techgdpr.com\/blog\/author\/anamika\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png",1408,604,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1-300x129.png",300,129,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1-768x329.png",640,274,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1-1024x439.png",640,274,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png",1408,604,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png",1408,604,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png",200,86,false]},"post_excerpt_stackable_v2":"<p>How, exactly, can privacy be designed?&nbsp;Companies concerned about Europe&#8217;s&nbsp;General Data Protection Regulation (GDPR) may or may not have already considered the curious concept of &#8220;privacy by design and privacy by default&#8221; \u2014 but consider it, they must. While it&#8217;s hardly the most charming regulatory text ever written, it&#8217;s implications are vast, and understanding it properly saves startups considerable time and money (and headaches) if they begin implementing a few key privacy procedures while they are still at earlier stages of product and procedural development.&nbsp;The legal nuts and bolts can be found in&nbsp;Article 25 of the GDPR, with this excerpt below&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-subjects\/\" rel=\"category tag\">Data Subjects<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/iot\/\" rel=\"category tag\">IoT<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/privacy-by-design\/\" rel=\"category tag\">Privacy by Design<\/a>","author_info_v2":{"name":"Anamike Ved","url":"https:\/\/techgdpr.com\/blog\/author\/anamika\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What the GDPR&#039;s &#039;Privacy By Design&#039; Really Means for Your Business - TechGDPR<\/title>\n<meta name=\"description\" content=\"Written by Anamika Ved and Jesse van Mouwerik. The GDPR expects companies and other organizations to implement technical and organizational measures at their earliest stages of their design and their operations.\u00a0\u00a0But how does one actually implement &quot;Privacy by Design?&quot;\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What the GDPR&#039;s &#039;Privacy By Design&#039; Really Means for Your Business - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"Written by Anamika Ved and Jesse van Mouwerik. The GDPR expects companies and other organizations to implement technical and organizational measures at their earliest stages of their design and their operations.\u00a0\u00a0But how does one actually implement &quot;Privacy by Design?&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2018-08-31T09:52:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-02-22T17:09:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1408\" \/>\n\t<meta property=\"og:image:height\" content=\"604\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Anamike Ved\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Anamike Ved\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/\"},\"author\":{\"name\":\"Anamike Ved\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/7cce562f18c88cfe6bff39232c71c951\"},\"headline\":\"What the GDPR&#8217;s &#8216;Privacy By Design&#8217; Really Means for Your Business\",\"datePublished\":\"2018-08-31T09:52:29+00:00\",\"dateModified\":\"2024-02-22T17:09:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/\"},\"wordCount\":1287,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/TechGDPR-Main-Graphics-69-1.png\",\"articleSection\":[\"Data Subjects\",\"IoT\",\"Privacy by Design\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/\",\"name\":\"What the GDPR's 'Privacy By Design' Really Means for Your Business - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/TechGDPR-Main-Graphics-69-1.png\",\"datePublished\":\"2018-08-31T09:52:29+00:00\",\"dateModified\":\"2024-02-22T17:09:43+00:00\",\"description\":\"Written by Anamika Ved and Jesse van Mouwerik. The GDPR expects companies and other organizations to implement technical and organizational measures at their earliest stages of their design and their operations.\u00a0\u00a0But how does one actually implement \\\"Privacy by Design?\\\"\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/TechGDPR-Main-Graphics-69-1.png\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/TechGDPR-Main-Graphics-69-1.png\",\"width\":1408,\"height\":604},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/what-the-gdprs-privacy-by-design-really-means-for-your-business\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What the GDPR&#8217;s &#8216;Privacy By Design&#8217; Really Means for Your Business\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/7cce562f18c88cfe6bff39232c71c951\",\"name\":\"Anamike Ved\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/24cc55c702a83b20431214d86fe7708413281817eb90b957017074481a91ec2b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/24cc55c702a83b20431214d86fe7708413281817eb90b957017074481a91ec2b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/24cc55c702a83b20431214d86fe7708413281817eb90b957017074481a91ec2b?s=96&d=mm&r=g\",\"caption\":\"Anamike Ved\"},\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/anamika\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What the GDPR's 'Privacy By Design' Really Means for Your Business - TechGDPR","description":"Written by Anamika Ved and Jesse van Mouwerik. The GDPR expects companies and other organizations to implement technical and organizational measures at their earliest stages of their design and their operations.\u00a0\u00a0But how does one actually implement \"Privacy by Design?\"","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/","og_locale":"en_US","og_type":"article","og_title":"What the GDPR's 'Privacy By Design' Really Means for Your Business - TechGDPR","og_description":"Written by Anamika Ved and Jesse van Mouwerik. The GDPR expects companies and other organizations to implement technical and organizational measures at their earliest stages of their design and their operations.\u00a0\u00a0But how does one actually implement \"Privacy by Design?\"","og_url":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/","og_site_name":"TechGDPR","article_published_time":"2018-08-31T09:52:29+00:00","article_modified_time":"2024-02-22T17:09:43+00:00","og_image":[{"width":1408,"height":604,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png","type":"image\/png"}],"author":"Anamike Ved","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Anamike Ved","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/"},"author":{"name":"Anamike Ved","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/7cce562f18c88cfe6bff39232c71c951"},"headline":"What the GDPR&#8217;s &#8216;Privacy By Design&#8217; Really Means for Your Business","datePublished":"2018-08-31T09:52:29+00:00","dateModified":"2024-02-22T17:09:43+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/"},"wordCount":1287,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png","articleSection":["Data Subjects","IoT","Privacy by Design"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/","url":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/","name":"What the GDPR's 'Privacy By Design' Really Means for Your Business - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png","datePublished":"2018-08-31T09:52:29+00:00","dateModified":"2024-02-22T17:09:43+00:00","description":"Written by Anamika Ved and Jesse van Mouwerik. The GDPR expects companies and other organizations to implement technical and organizational measures at their earliest stages of their design and their operations.\u00a0\u00a0But how does one actually implement \"Privacy by Design?\"","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-69-1.png","width":1408,"height":604},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/what-the-gdprs-privacy-by-design-really-means-for-your-business\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"What the GDPR&#8217;s &#8216;Privacy By Design&#8217; Really Means for Your Business"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/7cce562f18c88cfe6bff39232c71c951","name":"Anamike Ved","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/24cc55c702a83b20431214d86fe7708413281817eb90b957017074481a91ec2b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/24cc55c702a83b20431214d86fe7708413281817eb90b957017074481a91ec2b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/24cc55c702a83b20431214d86fe7708413281817eb90b957017074481a91ec2b?s=96&d=mm&r=g","caption":"Anamike Ved"},"url":"https:\/\/techgdpr.com\/blog\/author\/anamika\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/1479","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=1479"}],"version-history":[{"count":27,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/1479\/revisions"}],"predecessor-version":[{"id":8153,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/1479\/revisions\/8153"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/1486"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=1479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=1479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=1479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}