Tech & Counsel

Learn/Product Advisory and Cross-Functional Work

Privacy by Design in the Product Room

About 14 minutes

Tech & Counsel provides education only. Nothing on this site is legal advice, and nothing here creates a solicitor–client relationship.

Waiting until a feature is built, then writing a memo, is how a company pays twice. Changing a shipped screen costs the sprint again. Privacy by design, as this course uses it, means the protection is in the first sketch: privacy as a default, not as a patch.

Ask for the wireframes. They are the drawings of the screens in order. Read them the way you would read a draft clause.

A non-compliant sketch bundles marketing email and third-party sharing into one pre-ticked box. A compliant sketch splits those choices and leaves them unticked. The difference is visible before anyone writes code.

Patterns to refuse

Pre-ticked consent. A default yes is not an affirmative act.

Misdirection. Accept is large and bright. Reject is a caption in a submenu.

Bundled consent. The app will not give the ride, or the loan, or the account unless the user also accepts promotional SMS. The core service and the extra tracking are different decisions.

Minimisation, said in the meeting

A loan app that asks for the contact list, the SMS inbox, and a social-media password is describing a want, not a necessity. The question to ask out loud is whether identity can be checked through a narrower route — for example a BVN check through an API — instead of copying a private message history. You are not there to be the department that only says no. You are there to say what the smaller design still achieves.

Create a free account to mark this lesson complete.