Privacy and Data Protection, a leading UK journal on practical data protection compliance issues, has featured in its latest edition an article by Robert Maddox and Stephanie Thomas on the hallmarks of effective data protection by design and default under the EU and UK GDPR.  The article encourages organisations to consider incorporating principles of data protection by design and default throughout the lifecycle of products and services that involve the processing of personal data by:

  • engaging early in the development stage;
  • ensuring cross-stakeholder collaboration to involve research, development, and product teams;
  • establishing processes to periodically revisit, review, and revise data protection compliance;
  • implementing clear and established design priorities and guardrails, including privacy notices;
  • designing for safety;
  • documenting considerations and decisions;
  • prioritising training and providing ongoing learning opportunities; and
  • understanding the international data privacy landscape beyond the EU and UK GDPR.

Several recommendations align with key observations from our coverage of the UK ICO’s 2023 privacy forum on data protection by design and default.

Read the full text of the article here.

To subscribe to the Data Blog, please click here.

The cover art used in this blog post was generated by DALL-E.

Author

Robert Maddox is a partner in Debevoise & Plimpton LLP’s Data Strategy & Security practice, based in London. In 2021 he was named to Global Data Review’s “40 Under 40” and is described as “a rising star” in cyber law by The Legal 500 US (2022). His practice focuses on cybersecurity incident preparation and response, internal investigations and regulatory defence. Mr. Maddox also advises on data strategy and compliance in the context of emerging technologies, including AI, and operational resilience matters. He can be reached at rmaddox@debevoise.com.

Author

Stephanie D. Thomas is an associate in the Litigation Department and a member of the firm’s Data Strategy & Security Group and the White Collar & Regulatory Defense Group. She can be reached at sdthomas@debevoise.com.