Skip to content
atlas

Don't confuse these

Privacy by design vs Security by design

Why they differ

Security by design protects all systems and data; privacy by design is the GDPR principle focused on people's personal data and collecting less.

Privacy by design

Compliance & regulation

The GDPR principle that protection of personal data must be built into systems from the start.

Formal

The duty in GDPR Article 25 to build data protection into systems and processes from the design stage - for example by collecting less and hiding identities - and to make the most privacy-friendly setting the default.

In plain English

Drawing curtains into the plans for a new house, rather than taping newspaper over the windows after moving in.

In practice

Developers building a Danish municipality's booking form for sports halls drop the CPR number field the task does not need and leave the newsletter box unticked by default.

Why it matters

Data never collected cannot leak, and fixing privacy after launch costs far more than planning it in; it also makes the system easier to defend when Datatilsynet asks.

Security by design

Fundamentals

Thinking security into systems and processes from the very start, instead of adding it at the end.

Formal

The principle that security needs are set out and met in every stage of building a system or process - from first idea through design, building and running it - with safe settings as the default.

In plain English

Like planning the wiring before the walls go up - doing it later means tearing down walls.

In practice

Before a Danish municipality has a new self-service portal built for citizens, the project group requires MFA for staff logins and storing as little personal data as possible, and writes both into the supplier contract.

Why it matters

Fixing a weakness after launch costs far more than avoiding it on paper, and some weaknesses cannot be fixed at all without starting over.

Atlas is in beta.