Privacy by design is the practice of building data protection into a product, system, or process from the start, using seven foundational principles Dr. Ann Cavoukian set out in the 1990s. GDPR Article 25 later turned its core requirement into binding law for organizations the regulation covers.
Below: what the framework requires, where it came from, and how it differs from privacy by default. Then what it means for a website that mostly collects cookies and form data.
What Does Privacy by Design Mean?
Privacy by design means considering and embedding data protection at the design stage of any system, product, service, or process. It carries through the entire lifecycle, so privacy is the default rather than an afterthought. It is proactive, not reactive: risks get addressed before a product ships, not patched after a breach.
The idea covers more than software. It applies to information technology, business practices, and physical infrastructure alike. A company practices privacy by design when it asks what personal data a task needs, and how to protect it, during planning. It does not wait for a regulator or a breach to force the question.
This proactive posture is what distinguishes privacy by design from compliance-driven privacy work. Compliance-driven teams check requirements against a finished product. Privacy by design teams build the requirements into the product itself.
Why Privacy by Design Matters
Building privacy in from the start costs less, reduces breach risk, and builds more user trust than retrofitting it after a problem surfaces. The UK Information Commissioner's Office (ICO) lists four concrete paybacks for following this approach.
Privacy by design's return shows up in several places, not just avoided fines.
- Lower long-term costs. It prevents the need for large-scale redesigns when data protection issues surface late.
- User trust as a market differentiator. Confidence in how you handle data can make it easier to scale and to win privacy-conscious customers.
- Easier procurement in regulated markets. Sectors such as healthcare increasingly require documented data protection practices before they will sign a contract.
- A factor in regulatory decisions. The ICO says it weighs your data-protection-by-design measures when deciding whether, and how hard, to act on a violation.
A data breach is the clearest failure mode this approach prevents. Systems that collect and protect only what they need expose less when something goes wrong.
Where Privacy by Design Came From (Ann Cavoukian and the IPC of Ontario)
Privacy by design was developed by Dr. Ann Cavoukian while she served as Information and Privacy Commissioner of Ontario, Canada. She first coined the term in the 1990s, when embedding privacy into technology was far less common than a strict regulatory approach. In her own words, she "developed the term Privacy by Design back in the '90s."
The framework traces to 1995. That year, Cavoukian's office published joint research with the Dutch Data Protection Authority. The two coined the term "privacy-enhancing technologies" in that work.
The seven foundational principles that define the framework today were formally published in 2009. In 2010, the International Assembly of Privacy Commissioners and Data Protection Authorities unanimously adopted a resolution recognizing privacy by design as an international standard.
Privacy by design started as Cavoukian's own methodology, not a piece of legislation. Lawmakers wrote its core idea into binding law only later, through the GDPR's Article 25, covered next.
The 7 Foundational Principles of Privacy by Design
Privacy by design rests on seven foundational principles, set out by Ann Cavoukian in her original framework document. Each principle is named verbatim below, with a plain explanation.
| Principle | What it means |
|---|---|
| 1. Proactive not Reactive; Preventative not Remedial | Anticipate and prevent privacy problems before they happen, instead of fixing them after the fact. |
| 2. Privacy as the Default Setting | Personal data stays protected automatically. A user who does nothing still keeps their privacy intact. |
| 3. Privacy Embedded into Design | Privacy is built into the architecture itself, not added on afterward. |
| 4. Full Functionality: Positive-Sum, not Zero-Sum | Privacy and functionality both get delivered in full; the framework rejects trading one off against the other. |
| 5. End-to-End Security: Full Lifecycle Protection | Data stays protected from collection through secure disposal, with no gaps. |
| 6. Visibility and Transparency | Operations stay open and verifiable, so users and providers alike can confirm the system does what it promises. |
| 7. Respect for User Privacy | The system stays user-centric: strong defaults, clear notice, and accessible choices for the individual. |
These seven privacy-by-design principles are not the same set as the seven GDPR data-protection principles in Article 5. Article 5 governs how you may lawfully process personal data day to day: lawfulness, purpose limitation, data minimisation, and similar rules.
Privacy by design is a different thing: the engineering and organizational framework for building systems that make that processing safe from the start. For the Article 5 principles themselves, see what is data processing.
Is Privacy by Design a Law? Privacy by Design and GDPR Article 25
Privacy by design itself is a framework, not a statute. Its core requirement is written into binding law for anyone the EU's General Data Protection Regulation (GDPR) covers. Article 25, titled "data protection by design and by default," turns the framework's proactive posture into a legal obligation.
Article 25(1) requires appropriate technical and organisational measures. You weigh these against the state of the art and the cost of implementation. You also weigh the nature, scope, context, and purposes of the processing, and the risks to people's rights and freedoms.
Article 25(2) adds the "by default" half: by default, you may process only the personal data necessary for each specific purpose. That default obligation covers four things specifically.
- The amount of personal data collected
- The extent of its processing
- The period it is stored
- The degree of its accessibility
Recital 78 names pseudonymisation and encryption as example measures, though the regulation does not prescribe an exhaustive checklist.
In the United States, no single federal law uses the phrase "privacy by design," but state privacy laws increasingly expect the same posture in practice. See the full regulations map for how these obligations vary by jurisdiction.
Privacy by Design vs Privacy by Default: What's the Difference?
Privacy by design is the whole framework: engineering a system so privacy is built in from planning through disposal. Privacy by default is one principle inside that framework. It is also its own GDPR obligation under Article 25(2): the most privacy-protective settings apply automatically, with no action required from the user.
| Privacy by Design | Privacy by Default | |
|---|---|---|
| Focus | How the system is built and engineered | How the system behaves for the user out of the box |
| Action | Embedding privacy into architecture at the planning stage | Automatically applying the most privacy-protective settings |
| Example | Designing a system to collect the minimum data it needs | Shipping a new profile set to private, not public, by default |
Both reject dark patterns. The ICO's guidance is explicit: avoid harmful design practices that use language or colour to influence a user's decision, such as nudging or biased framing. Default settings should always offer strong privacy protections.
On a website, a cookie banner that loads nothing non-essential until the visitor opts in is privacy by default in action. The banner itself, and the minimal-data approach behind it, is privacy by design.
Privacy by Design Examples
Privacy by design shows up in features many people already use, each built on one of the seven principles.
- Data minimisation: an e-commerce site asks for a delivery address at checkout, not at signup, because it only needs the address once an order exists.
- Privacy by default: a social network sets new profiles to private rather than public, so the user has to choose to open up, not choose to lock down.
- End-to-end encryption: a messaging app like Signal encrypts messages so only the sender and recipient can read them, not even the service provider.
- Anonymisation and pseudonymisation: a fitness app replaces a user's name with a random ID before running analytics on their activity data.
- Granular consent: Apple's App Tracking Transparency blocks cross-app tracking by default and asks permission per app, rather than tracking first and offering an opt-out later.
A cookie banner that lets visitors accept or reject tracking by category is the version of this most small websites meet first. Cookies and trackers are usually the first personal data a new site collects.
Who Has to Follow Privacy by Design, and When?
Under GDPR Article 25, the duty falls on the data controller: the organization that decides why and how personal data gets used. Processors are not directly bound by Article 25. But a controller may only use processors that give sufficient guarantees they meet the GDPR. That requirement cascades the duty to processors in practice, through the Article 28 contract between them.
Implementation starts at the earliest planning stage of any system, service, product, or process. It continues throughout the entire lifecycle, not bolted on right before launch.
That timing question comes up often on the controller-versus-processor point too. On Reddit's r/gdpr, one developer asked whether an AI system they built as a processor still had to follow these principles.
The consensus answer matched the ICO's guidance directly: the direct Article 25 duty sits with the controller. A processor is bound indirectly, through the Article 28 agreement each controller must put in place.
The obligation applies regardless of company size if you process the personal data of people the GDPR protects. The same expectation is spreading beyond the EU. AI governance discussions and US state privacy laws increasingly echo this by-default posture, even without naming the framework.
Common Privacy by Design Misconceptions
A few myths about privacy by design persist even among people who work with data regularly.
- "Privacy by design means forced or all-or-nothing consent." It is the opposite. The framework and its default-setting principle explicitly forbid dark patterns and pre-ticked boxes; genuine, granular choice is required, not coerced consent.
- "Privacy by design is the same as the GDPR data-protection principles." It is not. Article 5's seven principles govern how you process data day to day; privacy by design is the separate engineering framework codified in Article 25.
- "Privacy by design requires pseudonymisation and encryption specifically." Those are example measures named in Recital 78, not a fixed checklist. The right measures depend on your processing and its risks.
- "Privacy by design only matters for big tech or large enterprises." It applies to any controller processing personal data the GDPR covers, including a small business running a single website.
What Privacy by Design Means for Your Website
For most small and mid-sized websites, the personal data actually collected is cookies, trackers, and form submissions. Privacy by design in practice comes down to a short list of concrete habits.
- Only load tracking scripts and cookies after a visitor agrees to them, which is privacy by default applied to your site.
- Collect only the form fields a task genuinely needs, which is data minimisation.
- Tell visitors plainly what you collect and let them change their mind later, which covers transparency and control.
- Keep a record of what each visitor consented to, which is the accountability piece regulators expect.
That pattern matches how practitioners describe it in day-to-day work. In practice, it comes down to automated consent management and lightweight banners that do not hurt conversion rates. One r/gdpr practitioner summed the goal up as "reducing friction."
For the specific requirements this creates, see the GDPR's rules for cookie banners. For the full compliance checklist, see how to bring your website into GDPR compliance.
How Consently Helps You Put Privacy by Default Into Practice
Consently does not make your whole product privacy by design. For the surface most websites hit first, cookies and trackers, it handles the "by default" piece: nothing non-essential loads until a visitor explicitly agrees.
Consently's cookie banner with automatic blocking stops non-essential cookies, scripts, and iframes from loading until the visitor opts in. That makes the privacy-protective state the default, with no pre-ticked boxes and no tracking by surprise. This is privacy as the default setting, applied to the one data source almost every website collects.
The preference center gives visitors granular accept-or-reject control by cookie category, plus a way to revisit and change their choice later. That covers the transparency and user-control side of the framework.
Consent logs record each visitor's choice with a timestamp, and export the full history. That gives you the accountability record GDPR Article 25 expects, without building that logging yourself.
Try Consently Free to see the auto-blocking banner and consent logs running on your own site. The trial runs 14 days, and no credit card is required.
FAQs
What is privacy by design in simple terms?
Privacy by design means building data protection into a product, system, or process from the start instead of adding it later. It shifts privacy from a reactive fix to a default feature of how something is built.
What are the 7 principles of privacy by design?
The 7 principles are:
- Proactive not reactive
- Privacy as the default setting
- Privacy embedded into design
- Full functionality (positive-sum)
- End-to-end security
- Visibility and transparency
- Respect for user privacy
See the table above for detail on each.
Who created privacy by design?
Dr. Ann Cavoukian created privacy by design while serving as Information and Privacy Commissioner of Ontario, Canada. The framework traces to 1995, with the seven foundational principles formally published in 2009.
Is privacy by design a legal requirement?
Privacy by design itself is a framework, not a law. GDPR Article 25 makes its core requirement, data protection by design and by default, a binding legal obligation for any organization the GDPR covers.
What is the difference between privacy by design and privacy by default?
Privacy by design is the whole framework for building privacy into a system from planning through disposal. Privacy by default is one principle within it, and its own GDPR Article 25(2) obligation, requiring the most privacy-protective settings to apply automatically.
What is an example of privacy by design?
A cookie banner that loads no non-essential tracking scripts until the visitor opts in is a common example. It combines data minimisation with privacy as the default setting.
When should privacy by design be implemented?
Implementation should start at the earliest planning stage of a system, product, or process. It continues throughout the entire lifecycle, not added shortly before launch.
Does privacy by design apply to small websites?
Yes, if the site processes the personal data of people the GDPR protects, regardless of the business's size. A small site collecting cookies and form data is a controller under Article 25 the same as a large enterprise.
