Privacy by Design and by Default
The law requires protection by default (s. 9.1) and profiling technologies that are off by default (s. 8.1). In practice this becomes design rules.
Design rules
- Explicit opt-in: no pre-checked boxes; refusing is as easy as accepting.
- Minimization: every form field and database column has a documented purpose.
- Least privilege (RBAC): a role sees only the data its task needs; access reviewed regularly.
- Environment separation: no real data in dev/test without anonymization.
- Protective defaults: private profile, telemetry off until consent is given.
Test data
Use synthetic data (e.g. the Faker library) or anonymized copies (e.g. the PostgreSQL Anonymizer extension), never a raw production dump.
from faker import Faker
fake = Faker("en_CA")
user = {"name": fake.name(), "email": fake.email(), "phone": fake.phone_number()}
Traceable consent
Record who consented, to what, when, with which version of the text, and allow withdrawal:
CREATE TABLE consent_log (
id uuid PRIMARY KEY,
subject_id uuid NOT NULL,
purpose text NOT NULL,
policy_version text NOT NULL,
granted boolean NOT NULL,
recorded_at timestamptz NOT NULL DEFAULT now()
);
Pre-production checklist: minimized fields? opt-in? logs free of PI? test data anonymized? retention defined? new third party validated by the RPRP? See the toolbox.