What this covers
Data privacy by design is a process change before it is a technical one. The assessment has to happen early enough in the lifecycle to influence architecture, and it has to be light enough that teams do not route around it.
- Screening gates placed at the points in your SDLC where design is still cheap to change
- DPIA and TIA execution for cloud platforms, web applications and generative AI systems
- Data minimisation and purpose limitation applied at schema level
- Consent and preference architecture that propagates downstream
- Default settings reviewed against the "privacy by default" requirement
- Engineering guidance the team can apply without a lawyer in the room
How it runs
Typically an embedded engagement: I sit with the product and engineering teams through a release cycle, run the first assessments alongside them, and hand over a process they own.
What you get
Assessments that change designs, an audit trail of the decisions, and engineering teams who can answer data privacy questions without escalating every one.