Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Lawscot Foundation

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Our logo and branding

    • Equality and diversity

  1. Home
  2. News and events
  3. Law Society news
  4. GDPR - Privacy by design and default... So what does this mean in practice?

GDPR - Privacy by design and default ... So what does this mean in practice?

23rd February 2018 | Professional support | Data protection

Deborah Dillon, EU Data Privacy and GDPR Executive Consultant at Atos, explains 'privacy by design' and 'privacy by  default' and what this means for your organisation.

One of the key changes to be brought into the General Data Protection Regulation (GDPR) is that of “Privacy by Design” along with “Privacy by Default”. Basically, companies will now be obliged to take into account data privacy during design stages of all projects along with the lifecycle of the relevant data process.

For me personally, as a privacy person, this is a great concept. So many times in the past has a system been developed either in-house or nationally, where the final sign off lies with me – only for me to go back to the developers and say “you can’t do that with personal information!”. 'Grim Reaper to projects' was almost a term of endearment.

With “Privacy by Design and Default”, my Grim Reaper position vanishes! I am asked to help undertake a Privacy Impact Assessment with the development team right at the start of the project/system design.  

This implementation does not necessarily mean that an organisation must spend a large proportion of its project budget on this design, but to take more of a risk-based approach, taking into account the nature, purposes, context, and scope of the processing and their implications. This seems to be the preferred attitude of organisations due to the flexibility it affords, but it is yet to be tested, so caution should be advised here.

When deciding this, organisations should take into consideration a wide range of factors regarding the processing of personal data including the ease of collection, how the data can be suppressed (for example, if a customer chooses to not receive direct marketing) or how portable the data is under the GDPR.

Alongside the “Privacy by Design” issue lays the “Privacy by Default” obligation. Under this obligation, data controllers must implement appropriate measures both on a technical and organisation level to ensure that personal data collected is only used for the specific purpose mentioned. This means that the minimum required amount of personal data should be collected, minimise the processing and control their storage and accessibility.

So to summarise, the concept of Privacy by Design shouldn’t be too much of an issue for organisations which already possess a strong privacy policy and take data breaches into account when building new systems. However, the GDPR now makes this design mandatory rather than advisory, so being prepared is highly important and I can now take my cloak off and put down my scythe.

GDPR

Our guide to data protection from the perspective of a legal practice

Read more about GDPR
Add To Favorites

Additional

Categories

  • New lawyers
  • Law Society news
  • Regulation
  • Research and policy
  • Legal aid
  • Professional support
  • Wellbeing
  • Business support
  • Equality and diversity
  • International
  • In-house lawyers
  • Schools
  • For the public
  • Videos
  • Fraud alerts
  • Career growth
  • Member benefits
  • Law and technology
  • Professional skills courses
  • Aberdeen
  • Edinburgh
  • Glasgow
  • Perth
  • Inverness
  • Commercial skills for young professionals
  • Roadshow
  • CPD event
  • Working in-house
  • Public Policy Committee
  • Roadshows
  • careers
  • property (non-commercial)
  • licensing
  • Journal online news
  • Sustainability
  • Policy committees

News Archive

  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015
  • 2014
  • 2013

Related articles

  • Law Society members reach new career heights
  • New partnership bolsters Law Society sustainability commitment
  • Spring celebrations for newly accredited Law Society members
  • Celebrations at first banking and finance paralegal accreditation
Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: lawscot@lawscot.org.uk
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2025
Made by Gecko Agency Limited