A survey conducted this year by Cisco revealed that 94% of organizations believe their customers won’t buy from them if data is not properly protected and 95% of organizations say the benefits of investing in data privacy exceed costs, with the average organization realizing a 1.6x return on their privacy investment. Consumers are more likely to trust companies if their personal data is processed in a privacy friendly way that organizations can be proudly transparent about.
To ensure privacy friendly practices organizations must seek to ensure their products, processes and related systems capture and reflect privacy requirements and principles in their design. In the context of building products this combination of efforts is commonly referred to as Privacy by Design (PbD) and explicitly referenced as an obligation in article 25 of the GDPR.
In practice organizations are beginning to adopt a shift left approach to privacy requirement’s that aims to ensure privacy requirements are captured earlier on in project timelines. Do you want a mature privacy program that operates proactively rather than reactively? In this blog I explain the origin of the shift left concept, what this concept means in a privacy context, what the benefits are and how to achieve this in practice.
The term "shift left" became popular in the context of software testing. Traditionally, testing was performed at the end of the software development lifecycle, which often resulted in discovering defects late when they were more costly and time-consuming to fix. The shift left approach advocates for integrating testing activities earlier in the development cycle, during the design and coding phases.
This is a concept that is well known in the security space and slowly filtering into the privacy community. Traditionally privacy compliance for many organizations has been reactionary or an afterthought. Privacy requirements are often identified late in project timelines. The business wants the privacy teams seal of approval at the end of the project design phase when it is too late or too costly to amend designs that failed to capture the privacy requirements early on.
The failure to consider privacy at the right time in a project timeline results in business decisions to either proceed accepting the privacy risks (e.g. data breaches, compliance issues and loss of customer trust) or abandon the project all together. Not only does this result in a bad project outcome it creates an unpleasant working environment for the teams collaborating on new business initiatives involving personal data.
The image below illustrate a standard project timeline, when in a project timeline specific privacy requirements are relevant and an example of what a project in practice following this methodology looks like.
Understanding where the privacy requirements have relevance in a project timeline helps pinpoint precisely when an organizations privacy process should be initiated and where in the primary infrastructure privacy requirements can be embedded. It also provides the project team with visibility on when consultation with an organisations Privacy Officer and Data Protection Officer will be necessary and constructive. The image above also demonstrates that the shift left concept is not only relevant for design requirements but also conducting legally required privacy assessments that assess requirements like legal basis in article 6 or meeting contractual obligations in article 28.
Shifting privacy considerations left or in otherwards considering privacy at the right time has considerable benefits including:
Ensuring privacy considerations occur at the correct stage during a project timeline requires a shared understanding of when in that timeline privacy requirements have relevance. The illustration above can be used as a tool to put project teams and privacy teams on the same page.
When this common understanding is achieved it will be important organizations established the following:
As privacy programs mature, and consumer expectations rise the need to shift privacy considerations left becomes increasingly necessary. Shifting privacy considerations left in project timelines ensures that privacy requirements are captured, understood and respected proactively in a cost effective and value adding way. Not only does this improve the quality of output it reduces risks and builds trust with consumers, employees or other data subjects whose data may be processed as part of a service or internal process.
Are you struggling to ensure privacy is considered at the right time during a business process or do you simply want to enhance your privacy governance framework and privacy program then please not hesitate to reach out. Considerati has a dedicated Privacy Officer service (see here) and DPOaaS (see here) that has been carefully designed to help organizations with varying degrees of maturity. We would be delighted to support you unlock the potential of shifting privacy left.
Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.
Our services ContactRecente blogs
The Dutch Data Protection Authority (AP) has imposed a fine of 6,000 euros on the recruitment company Ambitious People Group (APG) for not promptly responding…