Privacy by Design: Cheaper to Prevent Than to Remediate
Article 25 GDPR implementation: privacy by design and by default for digital products, software, apps, and internal processes. Direct integration with product and engineering teams.
Does this apply to your business?
Do your product and engineering teams consult the DPO or privacy advisor before beginning development of features that process personal data?
Is the default configuration of your products the most privacy-protective option, or do users have to actively search for how to reduce data sharing?
Have you defined data retention periods at every layer of your architecture (database, backups, logs, analytics) with a technical process to apply them automatically?
Does your development process include a privacy assessment before launching new features that might require a DPIA?
0 of 4 questions answered
Our privacy by design integration process
Privacy requirements analysis
In the product definition phase, we identify planned personal data processing activities, applicable legal bases, purposes, and data flows between systems, services, and third parties.
Compliant data architecture design
We define the data architecture that meets the principles of minimisation, purpose limitation, and storage limitation, and design the technical measures for pseudonymisation, encryption, and access control.
Impact assessment (if required) and design reviews
We determine whether the product requires a DPIA under Article 35 GDPR, conduct it where necessary, and participate in design reviews to verify that privacy requirements are maintained throughout development.
Launch and accountability documentation
We accompany the product launch with updated compliance documentation: privacy notices, informational clauses, records of processing activities, and DPIA report where applicable.
The challenge
Article 25 of the GDPR requires that data protection be considered from the moment of designing any product, service, or process that handles personal data. In practice, the vast majority of organisations follow the reverse sequence: they launch the product and then try to retrofit compliance onto an architecture that was not designed for it. The result is costly remediation, complex technical changes, and compliance that is frequently incomplete.
Our solution
We integrate privacy requirements into the product development cycle from the earliest design phases. We work directly with product, UX, and engineering teams to define the data architecture, technical and organisational measures, and information flows that ensure GDPR compliance without sacrificing product functionality.
Privacy by design and by default is a legally binding obligation under Article 25 of the EU General Data Protection Regulation (GDPR, Regulation 2016/679), which requires controllers to implement appropriate technical and organisational measures designed to give effect to data protection principles — such as data minimisation, purpose limitation, and storage limitation — both at the time of designing the processing and at the time of the processing itself. "Privacy by default" additionally requires that, by default, only personal data necessary for each specific purpose is processed. Failure to implement privacy by design and by default is a sanctionable GDPR infringement, independent of whether a data breach has occurred, and the AEPD has issued fines specifically for this violation.
Privacy by design is not a voluntary best practice — it is a legal obligation under Article 25 of the GDPR that creates liability for controllers who fail to implement it. And yet the majority of organisations continue to treat privacy as a post-development remediation exercise rather than a design requirement present from the earliest architectural decisions.
The True Cost of Getting the Sequence Wrong
The cost of the incorrect sequence is systematically underestimated. An architectural change that would have taken hours at the design stage — separating identification data from functional data, applying pseudonymisation from the source, implementing retention policies in the data model — can take weeks or months of engineering work when the system is already in production, with live data, dependent processes, and third-party contracts that constrain every change.
Beyond the direct engineering cost, post-launch privacy remediation is frequently incomplete. An architecture not designed for data minimisation cannot be made minimalist without rebuilding the data model. A system without audit logging cannot retroactively produce the access records that accountability requires. These structural deficiencies are visible to the AEPD in an inspection and are treated as evidence that privacy was not, in fact, built into the design.
Integration Without Bureaucracy
Our integration into product and engineering teams is structured around a lightweight process that generates real protections without bureaucratic overhead. For each new feature or product with a personal data component, we work with the team to answer four questions at the design stage: what data is collected and why, on what legal basis, for how long it is retained, and who has access. This exercise, conducted during design, rarely requires more than an hour. Conducted after launch, it can require weeks of audit and months of remediation.
The sprint review integration — where a privacy advisor reviews product demos when data processing changes are involved — is the mechanism that catches compliance issues when they are still inexpensive to address. A data field added to a user record, a new third-party integration, or a change to the analytics model can each trigger GDPR implications that are visible in a demo but invisible in a code review.
Privacy by Design for AI Systems
For artificial intelligence systems, data protection impact assessments and privacy by design are especially critical because the architecture decisions made at model design time determine whether the system can be GDPR-compliant in a structural sense. A model trained without data minimisation cannot be made minimalist retrospectively without complete retraining. Differential privacy, federated learning, pseudonymised training datasets, and explainable AI (XAI) design are tools that must be chosen at the outset — not added after the model is in production.
Privacy by default in the user experience is a component that product teams frequently underestimate. The product’s default privacy configuration is not just a legal requirement — it is also a signal to users of the organisation’s genuine commitment to their data. Platforms that share data with third parties by default, that activate advertising tracking without consent, or that make privacy controls difficult to find generate greater distrust and greater regulatory exposure than those that adopt the opposite model.
Real results from privacy by design implementation
When we started developing our occupational health app, we brought BMC in during the design phase. They defined the data architecture, conducted the DPIA, and reviewed every sprint with the team. We launched compliant from day one without a single post-launch architectural change. Far less expensive than waiting.
Experienced team with local insight and international reach
What our privacy by design service includes
Development Cycle Integration
Defining the privacy process for agile teams: privacy review criteria in the definition of done, privacy analysis templates for new features, and workshops for product and engineering teams.
Compliant Data Architecture
Design or review of the product's data architecture to ensure the principles of minimisation, purpose limitation, storage limitation, and pseudonymisation or encryption where applicable.
Privacy by Default in UX
Review of the user experience design to ensure that default settings are the most protective and that the interface does not incorporate dark patterns that undermine consent.
Data Protection Impact Assessment
Determination of the DPIA requirement and, where triggered, completion of the assessment integrated into the design process before development begins.
Accountability Documentation
Records of processing activities update, product privacy notice drafting, and documentation of technical and organisational measures implemented.
Results that speak for themselves
Commercial debt portfolio recovery
92% portfolio recovery in 4 months, with out-of-court settlements in 78% of cases.
Comprehensive employment defense for industrial multinational
100% favorable outcomes: 5 advantageous conciliation agreements and 3 fully upheld court rulings.
GDPR compliance programme for a hospital group: from investigation to full compliance
AEPD investigation closed with no sanction. Full GDPR compliance achieved across all group centres within 6 months.
Analysis and perspectives
Frequently asked questions about privacy by design
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Privacy by Design
Legal
First step
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Request your diagnostic
You may also be interested in
EU AI Act Compliance
Full compliance with the EU Artificial Intelligence Act: risk classification, conformity assessments, transparency obligations, and prohibited practice audits.
Saber másCriminal Compliance
Corporate criminal compliance programmes to exempt or mitigate the criminal liability of legal entities under Article 31 bis of the Spanish Criminal Code.
Saber másCybersecurity Audit
Security posture assessment, compliance audits (ENS, ISO 27001, NIS2), vulnerability assessment, penetration testing management, and third-party risk evaluation.
Saber másData Protection & Privacy
GDPR and LOPDGDD compliance, outsourced DPO, and comprehensive privacy management for businesses.
Saber másKey terms
EU AI Act
The EU Artificial Intelligence Act (Regulation EU 2024/1689) is the world's first comprehensive…
Read definitionData Protection Officer (DPO)
A Data Protection Officer (DPO) is a designated individual responsible for overseeing an…
Read definitionPrivacy by Design
A GDPR principle (Article 25) requiring data protection to be integrated into the design of…
Read definitionStandard Contractual Clauses (SCCs)
Model contracts adopted by the European Commission that provide adequate safeguards for transferring…
Read definition