§1
Privacy by design in software
Article 25 of the GDPR requires data protection by design and by default. For software teams, this means privacy is considered when features are designed, not added afterward. The most effective measure is collecting less data: every field that is not needed is one less thing to protect, explain, retain and eventually delete.
Defaults matter. Optional data sharing, marketing preferences and profile visibility should be off unless the user chooses otherwise. Access to personal data inside the organization should follow least privilege, with sensitive fields masked for roles that do not need them.
Retention should be designed into the data model. Each category of personal data needs a defined retention period based on its purpose and legal obligations, with automated deletion or anonymization when that period ends. Manual cleanups rarely happen consistently. Security of processing completes the picture. Encryption, access controls, logging, backups and regular testing are expected safeguards, proportionate to the risk. Documenting these decisions in records of processing and impact assessments demonstrates accountability, another core GDPR principle.

