Before coding a new customer portal, the team decides data fields to collect, default encryption, and role-based access as design choices—not afterthoughts. Which GDPR concept do these choices best illustrate?
Select an answer to reveal the explanation.
Short Explanation
Building privacy into the blueprint—fewer fields, encryption on, tight roles—is like putting seatbelts in the car at the factory, not taping them on after the crash. That's privacy by design in everyday engineering talk.
Full Explanation
Data protection by design and by default requires implementing appropriate measures—such as data minimisation, pseudonymisation or encryption, and access controls—designed into processing from the outset. Choosing those controls before coding operationalises PbD. Adequacy decisions and EDPS prior authorisation for private portals are not what this scenario illustrates.