Privacy by Design

Data minimisation, default protection and purpose binding as structural decisions.

6Questions
10Flashcards
1Terms
Questions

6 to work through

  1. beginner Multiple choice

    A food-delivery app of Zomato's shape must refuse alcohol orders to under-18s. The sign-up form asks for a full date of birth and the team is about to store it on the user row alongside the address. What should the account record hold instead, and what does the full date of birth cost you later?

    3 min answer
  2. intermediate

    Product wants to add a recommendation feature using browsing history. Legal asks for a data protection impact assessment. What does architecture need to supply?

    2 min answer
  3. advanced

    A privacy review finds that a customer's date of birth and partial bank details are visible in session-replay recordings for a subset of users, although the analytics vendor's configuration masks those fields. It affects roughly 3% of sessions, all on one flow. Where do you look, and what does the pattern tell you?

    3 min answer
  4. advanced

    On 20 March 2023 a change to OpenAI's servers spiked Redis request cancellations, a redis-py bug returned another user's cached reply on a pooled connection, and chat titles plus payment details of roughly 1.2% of active ChatGPT Plus subscribers were exposed during a nine-hour window. Which design decision turned a client-library bug into a personal-data breach?

    3 min answer
  5. advanced

    What does privacy by design mean architecturally rather than as a policy statement, and which decisions must be made first?

    2 min answer
  6. advanced

    What does privacy by design mean concretely at the point of designing a system, rather than as a principle?

    1 min answer
Regulatory & Data Protection Architecture

Neighbouring topics

Regulatory & Data Protection Architecture

General material on designing under legal and regulatory obligation.

3 quiz 9 cards 2 terms

Lawful Basis & Purpose Limitation

Why you may hold the data, and why that forbids the second use somebody proposed.

3 quiz 8 cards 4 terms

Data Subject Rights

Access, correction, portability and erasure across systems that never planned for them.

4 quiz 6 cards 4 terms

Consent Architecture

Capturing, versioning and propagating consent to every system that acts on the data.

5 quiz 9 cards 3 terms

Data Residency

Keeping data within a jurisdiction, including backups, logs and support access.

7 quiz 11 cards 2 terms

Digital Sovereignty

Control over data, operations and the operator, beyond where the bytes physically sit.

4 quiz 9 cards 3 terms

Cross-Border Transfer

The legal mechanism that permits data to leave, and the architecture that respects it.

4 quiz 6 cards 4 terms

PCI-DSS Scoping

Segmentation and tokenisation to shrink what is in scope, because scope is the cost.

6 quiz 8 cards 4 terms

Healthcare Data Protection

PHI handling, minimum necessary access, and audit expectations in clinical systems.

4 quiz 10 cards 3 terms

Financial Services Regulation

Operational resilience, payment rules and supervisory expectations as design inputs.

4 quiz 11 cards 3 terms

Records Retention & Legal Hold

Keeping what must be kept, deleting what must go, and freezing both on demand.

5 quiz 9 cards 4 terms

Erasure vs Immutability

Deletion obligations against event logs, backups and ledgers designed never to forget.

4 quiz 12 cards 2 terms

Pseudonymisation

Separating identity from record, and the re-identification risk that remains.

4 quiz 9 cards 4 terms

Privacy-Enhancing Technologies

Differential privacy, secure enclaves and federated computation, and what each buys.

4 quiz 8 cards 5 terms

Regulatory Reporting Pipelines

Submissions with fixed deadlines, fixed formats, and a regulator who audits the lineage.

4 quiz 6 cards 4 terms

Sector Cloud Rules

Regulator expectations for cloud use, exit plans and material outsourcing notification.

4 quiz 7 cards 4 terms

Exit & Concentration Risk

Being able to leave a provider, and what the regulator asks when you cannot.

6 quiz 9 cards 2 terms

Third-Party Risk

Assessing, contracting and monitoring the vendors your architecture now depends on.

5 quiz 7 cards 4 terms

Geo-Restriction & Sanctions

Blocking access by jurisdiction, and the accuracy and evasion problems that come with it.

4 quiz 10 cards 3 terms