survey conducted this year by Cisco revealed that 94% of organizations believe their customers won’t buy from them if data is not properly protected and 95% of organizations say the benefits of investing in data privacy exceed costs, with the average organization realizing a 1.6x return on their privacy investment. Consumers are more likely to trust companies if their personal data is processed in a privacy friendly way that organizations can be proudly transparent about.  

To ensure privacy friendly practices organizations must seek to ensure their products, processes and related systems capture and reflect privacy requirements and principles in their design. In the context of building products this combination of efforts is commonly referred to as Privacy by Design (PbD) and explicitly referenced as an obligation in article 25 of the GDPR. 

In practice organizations are beginning to adopt a shift left approach to privacy requirement’s that aims to ensure privacy requirements are captured earlier on in project timelines. Do you want a mature privacy program that operates proactively rather than reactively? In this blog I explain the origin of the shift left concept, what this concept means in a privacy context, what the benefits are and how to achieve this in practice.  

Adopting the shift left concept  

The term "shift left" became popular in the context of software testing. Traditionally, testing was performed at the end of the software development lifecycle, which often resulted in discovering defects late when they were more costly and time-consuming to fix. The shift left approach advocates for integrating testing activities earlier in the development cycle, during the design and coding phases. 

This is a concept that is well known in the security space and slowly filtering into the privacy community. Traditionally privacy compliance for many organizations has been reactionary or an afterthought. Privacy requirements are often identified late in project timelines. The business wants the privacy teams seal of approval at the end of the project design phase when it is too late or too costly to amend designs that failed to capture the privacy requirements early on.   

The failure to consider privacy at the right time in a project timeline results in business decisions to either proceed accepting the privacy risks (e.g. data breaches, compliance issues and loss of customer trust) or abandon the project all together. Not only does this result in a bad project outcome it creates an unpleasant working environment for the teams collaborating on new business initiatives involving personal data. 

A visual illustration of shifting privacy left  

The image below illustrate a standard project timeline, when in a project timeline specific privacy requirements are relevant and an example of what a project in practice following this methodology looks like. 

Understanding where the privacy requirements have relevance in a project timeline helps pinpoint precisely when an organizations privacy process should be initiated and where in the primary infrastructure privacy requirements can be embedded. It also provides the project team with visibility on when consultation with an organisations Privacy Officer and Data Protection Officer will be necessary and constructive. The image above also demonstrates that the shift left concept is not only relevant for design requirements but also conducting legally required privacy assessments that assess requirements like legal basis in article 6 or meeting contractual obligations in article 28.  

Benefits of Shifting Privacy Left  

Shifting privacy considerations left or in otherwards considering privacy at the right time has considerable benefits including: 

  • Cost efficiency: Early detection and resolution of defects are much cheaper than fixing them later.  
  • Time efficiency: Accelerated project completion time by streamlining development cycles and reducing the need for extensive rework (and frustration). 
  • Quality: It enhances overall product quality by ensuring privacy friendly features and continuous testing and immediate issue resolution.  
  • Reduced risk: Designing privacy friendly activities and conducting privacy assessments ensures potential risks created for data subjects is avoided.  
  • Collaboration: It fosters better collaboration among cross-functional teams, which improves the development process and product outcomes.  
  • Compliance: Shifting privacy left helps organizations comply with appliable privacy rules and regulations and avoid potential legal and reputational damage. 
  • Consumer trust: builds trust with users and enhances brand reputation.  

Implementing Shift Left in Practice  

Ensuring privacy considerations occur at the correct stage during a project timeline requires a shared understanding of when in that timeline privacy requirements have relevance. The illustration above can be used as a tool to put project teams and privacy teams on the same page.  

When this common understanding is achieved it will be important organizations established the following: 

  • Privacy Team: Specialists who translate the privacy requirements during the define phase into terms that the business can understand, recommend risk mitigation measures, and ensure privacy assessments and data processing agreements are executed. 
  • Privacy Processes: Documented and senior management-endorsed processes support collaboration and clarify responsibilities. Best practices include Privacy Intake Questionnaires, Privacy by Design Workshops, Privacy Assessments, Third Party Due Diligence, Data Subject Request Procedures, and Data Breach Procedures. 
  • Guidelines, Templates and Training Material: Resources that explain specific rules, best practices, and necessary privacy processes. Templates help the business respond to the requirements in practice. Privacy Playbooks for different audience groups ensures practical and actionable information. 
  • Embedding Privacy into primary Infrastructure: Integrate relevant privacy requirements into standard operating procedures, ensuring privacy is considered within existing workflows. Embedding specific and relevant privacy requirements into the first line of defense ensures the business are triggered to consider privacy in context that is convenient and familiar 
  • Utilizing Technology: Leverage IT infrastructure to enforce safeguards and automation. Technical safeguards ensure privacy requirements are documented before advancing stages and automate updates to maintain compliance. 

Conclusion  

As privacy programs mature, and consumer expectations rise the need to shift privacy considerations left becomes increasingly necessary. Shifting privacy considerations left in project timelines ensures that privacy requirements are captured, understood and respected proactively in a cost effective and value adding way. Not only does this improve the quality of output it reduces risks and builds trust with consumers, employees or other data subjects whose data may be processed as part of a service or internal process.  

Are you struggling to ensure privacy is considered at the right time during a business process or do you simply want to enhance your privacy governance framework and privacy program then please not hesitate to reach out. Considerati has a dedicated Privacy Officer service (see here) and DPOaaS (see here) that has been carefully designed to help organizations with varying degrees of maturity. We would be delighted to support you unlock the potential of shifting privacy left.   

James O'Neill Legal Manager

Do you want to know more?

Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.

Our services orContact