Privacy Design Strategies
Privacy Design Strategies are a set of high-level approaches for building privacy protection into the design of systems, technologies, and business practices from the outset, rather than adding it afterward. They give designers and engineers organizing goals to work toward when handling personal data. The strategies are often grouped into those focused on the data itself and those focused on the processes surrounding the data.
Privacy Design Strategies are a taxonomy of eight distinct, high-level objectives used in privacy engineering to operationalize privacy-by-design when architecting systems and processing activities. They are commonly divided into data-oriented strategies (typically identified as Minimise, Separate, Abstract/Aggregate, and Hide) and process-oriented strategies (typically Inform, Control, Enforce, and Demonstrate), though exact labels vary across formulations. In the framework advanced by Colesky and colleagues (2016), strategies sit at the highest level of abstraction, with an intermediate layer of 'tactics' proposed to bridge strategies to concrete privacy design patterns and their implementations. These strategies constitute a design methodology and organizing framework rather than a legal instrument; they are not defined in the GDPR text, and practitioners should treat them as a complement to, not a substitute for, the Regulation's data protection by design and by default obligations. The specific set of strategies and their naming should be verified against the source framework being applied, as formulations differ across the literature and guidance.
Why it matters
Privacy Design Strategies matter because they translate the abstract goal of privacy-by-design into a workable set of objectives that engineers and system architects can actually build toward. Data protection by design and by default is an obligation under the GDPR, but the Regulation does not prescribe specific technical methods for achieving it. Frameworks such as the eight Privacy Design Strategies help bridge that gap by giving practitioners organizing goals when they make architectural and process decisions about handling personal data, ideally before a system is built rather than after problems emerge.
Building privacy in from the outset is generally more effective and less costly than retrofitting it once a system is operational, because early design choices tend to constrain what protections are feasible later. By separating data-oriented objectives (such as minimising, separating, abstracting, and hiding personal data) from process-oriented ones (such as informing, controlling, enforcing, and demonstrating), the strategies help teams reason about privacy across both the data itself and the practices surrounding it. This structure can support accountability efforts, since strategies like 'demonstrate' align conceptually with the need to show compliance.
That said, these strategies are a design methodology and organizing framework, not a legal instrument. They are not defined in the GDPR text and should be treated as a complement to, rather than a substitute for, the Regulation's data protection by design and by default obligations. Formulations differ across the literature, so their value depends on being applied thoughtfully alongside the applicable legal requirements and a proper assessment of the specific processing context.
Who it's relevant to
Inside Privacy Design Strategies
Common questions
Answers to the questions practitioners most commonly ask about Privacy Design Strategies.