Compliance & regulation
The GDPR principle that protection of personal data must be built into systems from the start.
Formal
The duty in GDPR Article 25 to build data protection into systems and processes from the design stage - for example by collecting less and hiding identities - and to make the most privacy-friendly setting the default.
In plain English
Drawing curtains into the plans for a new house, rather than taping newspaper over the windows after moving in.
In practice
Developers building a Danish municipality's booking form for sports halls drop the CPR number field the task does not need and leave the newsletter box unticked by default.
Why it matters
Data never collected cannot leak, and fixing privacy after launch costs far more than planning it in; it also makes the system easier to defend when Datatilsynet asks.