1. Privacy by Design beginner Multiple choice

    A food-delivery app of Zomato's shape must refuse alcohol orders to under-18s. The sign-up form asks for a full date of birth and the team is about to store it on the user row alongside the address. What should the account record hold instead, and what does the full date of birth cost you later?

    3 min answer data-minimisationderived-attributesgdpr-article-25age-verification
  2. Privacy by Design advanced

    A privacy review finds that a customer's date of birth and partial bank details are visible in session-replay recordings for a subset of users, although the analytics vendor's configuration masks those fields. It affects roughly 3% of sessions, all on one flow. Where do you look, and what does the pattern tell you?

    3 min answer session-replaymaskingthird-party-scriptsdata-minimisation
  3. Privacy by Design advanced

    On 20 March 2023 a change to OpenAI's servers spiked Redis request cancellations, a redis-py bug returned another user's cached reply on a pooled connection, and chat titles plus payment details of roughly 1.2% of active ChatGPT Plus subscribers were exposed during a nine-hour window. Which design decision turned a client-library bug into a personal-data breach?

    3 min answer openaicacheconnection-poolbreach
  4. Privacy by Design intermediate

    Product wants to add a recommendation feature using browsing history. Legal asks for a data protection impact assessment. What does architecture need to supply?

    2 min answer privacydpiadesigncompliance
  5. Privacy by Design advanced

    What does privacy by design mean architecturally rather than as a policy statement, and which decisions must be made first?

    2 min answer jupiterprivacyminimisationdefaults
  6. Privacy by Design advanced

    What does privacy by design mean concretely at the point of designing a system, rather than as a principle?

    1 min answer privacyminimisationdesigndefaults