
What this article covers
Privacy by Design means deciding how data will be handled while a feature can still be changed. For a product team, those decisions need to appear in requirements, tests and operations as well as the privacy notice.
1. Start with the purpose of each field
Consider a form for requesting a demonstration. Contact requires a name and a way to reply; that does not automatically justify asking for an identity document, date of birth or sensitive information. Write down which decision or step each field enables.
If the team cannot explain a use, remove the field or reconsider its necessity. Distinguish required information from optional information without creating artificial barriers for people who provide less data.
2. Map the complete data path
Trace the journey from the browser to the support team, including CRM, email, application logs, analytics and exports. A field removed from the screen may still appear in a URL, log or third-party tool.
- List who needs access to each item and for how long.
- Separate test and production environments.
- Define request handling and deletion rules.
- Include suppliers and transfers in the assessment.
3. Turn principles into acceptance criteria
The necessity and security principles in Article 6 of Brazil’s LGPD, together with Article 46’s provision for measures from the design stage, inform this discussion in Brazil. Their application depends on the purpose and risk.
Example criteria: form data never appears in the URL; roles unrelated to support cannot access requests; technical logs omit unnecessary fields; a routine demonstrates disposal under the defined policy.
4. Test choices and failure conditions
Check optional tools before and after the user makes a choice. When a feature depends on consent, also test rejection, withdrawal and an unavailable consent platform. A correct preferences screen is insufficient if a script has already sent data.
Submit a test request using fictitious data and follow every generated copy. Verify that an access or deletion response can reach the expected destinations, subject to applicable retention requirements.
5. Record the decision and follow changes
Record the approved purpose, necessary data, controls and owner of any accepted residual risk. Supplier changes or new uses require reassessment. Where risk warrants it, structure an impact assessment with the responsible teams.
Explore the governance approach of GRCtech and the compliance checklist to organize next steps. A feature needs to demonstrate its behavior, beyond declaring a commitment to privacy.
