{"id":2611,"date":"2022-10-25T11:43:00","date_gmt":"2022-10-25T17:43:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2611"},"modified":"2024-10-10T13:19:59","modified_gmt":"2024-10-10T19:19:59","slug":"7-privacy-by-design-guidelines","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/7-privacy-by-design-guidelines\/","title":{"rendered":"7 Priceless Privacy by Design Guidelines"},"content":{"rendered":"\t\t<section id=\"block_e3ac5f47fc625b69d7f8598b2fe65439\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>7 Priceless Privacy by Design Guidelines<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_8e747eb32ffdd970ca4835f1489b134a\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t<div class=\"person-wrap\">\n\t\t\t<span>\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"110\" height=\"110\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/people-placeholder-lt-blue.png\" class=\"attachment-full size-full wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t<strong class=\"block name\">Annie Greenley-Giudici<\/strong>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/span>\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<p>The concept of privacy by design was first introduced by the Canadian Privacy Commissioner\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Ann_Cavoukian\" target=\"_blank\" rel=\"noopener\">Ann Cavoukian<\/a>\u00a0as early as the 1990s. Since then, the importance of privacy by design in business has only increased.<\/p>\n<p>Lately, companies of all sizes are in the news because of data privacy violations. As a result, these brands often suffer reputation damage, even if the news got it wrong.<\/p>\n<p><strong>Assuming most companies are not intentionally doing things wrong, what is happening?<\/strong><\/p>\n<h2>The data privacy landscape is changing<\/h2>\n<p>A combination of governmental, media, and academic pressure is changing the way privacy is monitored by the community at large.<\/p>\n<p>There are now experts that are proactively looking for violations and using the mainstream media to get their message out quickly in a way to evoke change. It is no longer the average consumer you must consider in your risk calculation.<\/p>\n<p>So what is needed to achieve privacy by design? TrustArc has been helping companies to do it since 1997.<\/p>\n<h2>Seven principles to incorporate privacy by design into your product design process<\/h2>\n<h3>1. Proactive approach<\/h3>\n<p>Consider privacy at the design stage by examining how much information you are collecting and assessing whether you are collecting more information than what\u2019s necessary to achieve your business goals.<\/p>\n<p>Incorporating data privacy at the design stage will reap benefits down the road in terms of earning the trust of your consumers, and potentially keeping your company from incurring the unexpected costs associated with not taking privacy into account.<\/p>\n<p>Ringleader was a company with a promising future but didn\u2019t take data privacy into account at the design stage.\u00a0<a href=\"https:\/\/www.adexchanger.com\/mobile\/bob-walczak\/\" target=\"_blank\" rel=\"noopener\">They were forced to shut down<\/a>\u00a0because they didn\u2019t incorporate privacy into their, otherwise very promising, MediaStamp advertising tech.<\/p>\n<h3>2. Transparency<\/h3>\n<p>Be clear with consumers about your practices. Explain your information and collection processes in an easy to understand notice.<\/p>\n<p>Most companies typically do this through a\u00a0<strong>privacy policy<\/strong>\u00a0explaining what information you collect, how it is used, and to what third parties information is disclosed.<\/p>\n<p><strong>The privacy policy should be easy to find.\u00a0<\/strong>Make it accessible where information is requested such as on an order form. And it should be formatted so it\u2019s easy to read on any device.<\/p>\n<p>For example, if the consumer is accessing your policy through a mobile app, the policy should be optimized for viewing through a mobile device.<\/p>\n<h3>3. Control<\/h3>\n<p>Provide consumers mechanisms to express their preferences about how their information is used, and how to access that information to correct, updated, and\/or delete it.<\/p>\n<p><strong>Examples of some of the types of controls you can provide to consumers:<\/strong><\/p>\n<ul>\n<li>If you collect behavioral data to provide targeted advertising, you should give consumers an easy and effective way to express their preference to recieve targeted ads.<\/li>\n<li>If you collect\u00a0<a href=\"https:\/\/blog.trustarc.com\/2022\/03\/10\/personally-identifiable-information\/\" target=\"_blank\" rel=\"noopener\">personally-identifiable information<\/a>, your company should provide a way a user to correct his\/her profile or remove it.<\/li>\n<li>If you distribute software, consumers should have consented to install the software and then uninstall it completely from their systems.<\/li>\n<\/ul>\n<h3>4. Accountability<\/h3>\n<p>There are two types of accountability. Accountability\u00a0<strong>to your consumers<\/strong>, as well as accountability\u00a0<strong>within your organization<\/strong>.<\/p>\n<p>Posting a privacy policy outlining your privacy practices and giving consumers a mechanism to voice privacy-related concerns are a couple of ways your company can hold itself accountable to consumers.<\/p>\n<p>Put in place mechanisms that verifies whether your company is complying with its data controls and policies.<\/p>\n<p>Another layer if accountability is having an independent third party review and verify that your actual data privacy practices are consistent and comply with stated practices.<\/p>\n<p>A third party seal is a good outward indicator that communicates your company\u2019s commitment to privacy and that your company is willing to hold itself accountable to its privacy promises.<\/p>\n<h3>5. Data management<\/h3>\n<p>Make sure you have the processes in place to not only mange the data you collect but also to comply with your stated privacy promises.<\/p>\n<p><strong>Consider:<\/strong><\/p>\n<ul>\n<li><strong>Employee training<\/strong>: such as customer service representatives, who access collected information in order to perform their job function<\/li>\n<li><strong>Data Retention Policies<\/strong>: \u00a0how long you need to retain the information you collect.\n<ul>\n<li style=\"text-align: left\">Processes should be in place to periodically purge out-of-date or inactive customer records<\/li>\n<\/ul>\n<\/li>\n<li><strong>Security Measures<\/strong>: \u00a0what measures are in place to protect collected information.\n<ul>\n<li>Consider things such as how you will protect systems from vulnerabilities, whether information needs to be stored in an encrypted format, and who requires access based upon job function.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Processes should be appropriate for size of your business and the level of sensitivity of the information you collect and store on your systems.<\/p>\n<p>If you collect and store sensitive information like credit card numbers, you will need to take more stringent measures to protect that information than a company that collects only email addresses.<\/p>\n<h3>6. Partner and vendor risk management<\/h3>\n<p>Know who you work with. Have a\u00a0<a href=\"https:\/\/blog.trustarc.com\/2022\/07\/07\/vendor-risk-management-program\/\" target=\"_blank\" rel=\"noopener\">vendor risk management process<\/a>\u00a0for reviewing potential partners and vendors your company uses to provide services such as hosting, payment processing, email management, and advertising.<\/p>\n<p>These companies should have policies in place that are similar to yours to ensure the information you entrust to them is processed in a responsible manner.<\/p>\n<p><strong>Ultimately your company is responsible for the information it collects, and this includes third parties that are processing information on your company\u2019s behalf.<\/strong><\/p>\n<p>Develop criteria and have processes in place to review potential partners and vendors looking at how they process and protect the information that will be provided to these companies.<\/p>\n<h3>7. Respect for users<\/h3>\n<p>Your consumers are the reason why you have a business.<\/p>\n<p>They trust you will process their information for the purposes you stated in your privacy policy and do that in a responsible manner.\u00a0<strong>Trust is built over time but can be lost in an instant.<\/strong><\/p>\n<p>Your consumers might forgive you for one mistake but won\u2019t be so forgiving them next time around.<\/p>\n<p>One way to\u00a0<strong>make sure you retain that trust is that you start to earn it from the outset<\/strong>\u00a0\u2013 when you are designing your product or service.<\/p>\n<h2>Privacy by design is a bigger challenge than it appears<\/h2>\n<p>Largely this is because your company should think about it and invest into it in advance, before it finds itself in a Wall Street Journal article or in under investigation by a government regulator.<\/p>\n<p>Companies should, at minimum, create a privacy policy that accurately describes privacy practices, effective consumer control mechanisms to allow consumers exercise their preferences about their data, and processes to manage and protect the information collected.<\/p>\n<p>Furthermore, you should work only with trusted partners who do all the above.<\/p>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/data-privacy\/\" class=\"badge\">Data Privacy<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/privacy-governance\/\" class=\"badge\">Privacy Governance<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>What is needed to achieve privacy by design? Find out the 7 principles for incorporating privacy by design into your processes.<\/p>\n","protected":false},"featured_media":1260,"template":"","topic-resource":[55,56],"type-resource":[6],"class_list":["post-2611","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-data-privacy","topic-resource-privacy-governance","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>7 Priceless Privacy by Design Guidelines | TrustArc<\/title>\n<meta name=\"description\" content=\"What is needed to achieve privacy by design? Find out the 7 principles for incorporating privacy by design into your processes.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/7-privacy-by-design-guidelines\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/7-privacy-by-design-guidelines\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/7-privacy-by-design-guidelines\\\/\",\"name\":\"7 Priceless Privacy by Design Guidelines | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/7-privacy-by-design-guidelines\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/7-privacy-by-design-guidelines\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-woven-blue-test.png\",\"datePublished\":\"2022-10-25T17:43:00+00:00\",\"dateModified\":\"2024-10-10T19:19:59+00:00\",\"description\":\"What is needed to achieve privacy by design? Find out the 7 principles for incorporating privacy by design into your processes.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/7-privacy-by-design-guidelines\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/7-privacy-by-design-guidelines\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-woven-blue-test.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-woven-blue-test.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"7 Priceless Privacy by Design Guidelines | TrustArc","description":"What is needed to achieve privacy by design? Find out the 7 principles for incorporating privacy by design into your processes.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/7-privacy-by-design-guidelines\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/7-privacy-by-design-guidelines\/","url":"https:\/\/trustarc.com\/resource\/7-privacy-by-design-guidelines\/","name":"7 Priceless Privacy by Design Guidelines | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/7-privacy-by-design-guidelines\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/7-privacy-by-design-guidelines\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-woven-blue-test.png","datePublished":"2022-10-25T17:43:00+00:00","dateModified":"2024-10-10T19:19:59+00:00","description":"What is needed to achieve privacy by design? Find out the 7 principles for incorporating privacy by design into your processes.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/7-privacy-by-design-guidelines\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/7-privacy-by-design-guidelines\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-woven-blue-test.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-woven-blue-test.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2611","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1260"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2611"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2611"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}