Privacy by Design means that you Privacy PolicyData protection safeguards the personal data of natural persons from unlawful processing, misuse, and loss of control. For SMEs, data protection therefore means: You consciously decide which data you collect,... Click to learn more Consider data protection from the outset, during the conception, selection, and development of processes, websites, and tools, rather than retrofitting it later. For SMEs, Privacy by Design is not an abstract legal formula, but a practical rule for clean systems: A contact form, an analytics tool, a newsletter system, or a CRM Customer Relationship Management, often abbreviated to CRM, is a business strategy that encompasses everything related to your relationship with your customers. At its core, it's about... Click to learn more Data should only be processed that is truly necessary for the respective purpose. This is precisely how risks, corrections, and losses of trust are reduced.
Legally, the term is in Art. 25 DSGVO enshrined. The law speaks more precisely of “Data protection by design and by default”, also from Data protection by design and privacy-friendly default settingsThe common term "Privacy by Design" is technically correct, even though the legal text is formulated more precisely.
In practice, Privacy by Design means: design cleanly first, then collect data.
Privacy by Design according to Art. 25 GDPR
Art. 25 DSGVO requires that controllers, both when defining the processing and during the ongoing processing technical and organizational measures install. This includes protective mechanisms such as data minimizationAppropriate access rules, secure processes, and a design that protects the rights of data subjects. The EDPB emphasizes in its overview of Article 25 that these measures are essential. before the start The processing must be taken into account and then continuously monitored.
For an SME, data protection through technology design can be broken down into five simple review questions:
- Does the process really need this data? If not, remove fields, reduce interfaces, and shorten storage periods.
- Are the default settings conservative? So no pre-activated checkboxes, no unnecessarily open profiles, and no pre-set marketing tracking.
- Are roles and access restricted? Not every employee needs access to all customer data or applications.
- Is the provider properly integrated? With external tools, you often need a Data processing and clear responsibilities.
- Can the process still be explained later? Good technology not only protects data, but also makes the processing traceable and verifiable.
If you're redesigning your website anyway, a straightforward review of the fundamentals is often helpful. Ours Website checklist for SMEs This shows how strongly trust, clarity, and a legally sound structure are interconnected.
Privacy by Design vs. Privacy by Default
Privacy by Design and Privacy by default These terms are often mentioned together, but they don't mean the same thing. The distinction is important because many companies consider data protection during the planning phase, but ultimately publish overly permissive default settings.
- Purpose: Privacy by Design concerns the Design of the entire systemPrivacy by Default affects the default usage this system.
- Time: Privacy by Design begins near the introduction of a tool or process. Privacy by Default manifests itself during the first deployment in the specific settings.
- Practical implementation: Privacy by Design asks whether a tracking tool is even necessary. Privacy by Default asks whether tracking should remain disabled by default until valid consent is given.
- Example contact form: Privacy by Design reduces form logic to only the necessary data. Privacy by Default makes optional information truly optional and stores no more data than necessary.
- Example user account: Privacy by Design incorporates roles, deletion periods, and access control. Privacy by Default ensures that profiles are not automatically publicly visible.
In short: Privacy by Design provides the framework, Privacy by Default sets the secure starting point.
The seven principles according to Ann Cavoukian
The seven basic principles of Privacy by Design go on Ann Cavoukian back. Their center describes Privacy by Design as a concept developed since the 1990s and names seven foundations that are still frequently cited today.
- Proactive instead of reactive: Risks are identified early. In practice, this means checking which data a form, a PluginDefinition of a plugin: A plugin (also called a plug-in or plug-in) is an additional program (software) that is integrated into an existing software application to extend its functionality... Click to learn more or a booking tool that actually processes data.
- Data protection as standard: The most privacy-friendly setting is pre-selected. No marketing checkboxes are pre-selected, no profiles are unnecessarily open, and no tracking runs in the background without a clear legal basis.
- Data protection embedded in the design: Data protection is not an add-on. Data protection belongs in BriefingIf you want to create a briefing, you primarily need clarity: A briefing is a structured document or a coordinated conversation that outlines the goal, framework, etc. Click to learn moreConceptualization, selection of tools, rights management and documentation.
- Full functionality instead of either/or: Good solutions combine efficiency and security. You don't have to choose between good user experience and data protection if the system is well-designed.
- Protection throughout the entire life cycle: Data must be secured from collection to deletion. This includes retention periods, backups, access control concepts, and proper deletion processes.
- Visibility and Transparency: Users should be able to understand what is happening. This includes clear instructions and a comprehensible process. Consent Management and clearly communicated purposes.
- Respect for user rights: The interests of the data subject are paramount. This is reflected in simple choices, fair forms, and easily understandable data protection information.
What does Privacy by Design mean in practice?
From many projects with owner-managed businesses, I've observed a typical pattern: The problem isn't malicious intent, but rather a hodgepodge of plugins, forms, and third-party tools that has accumulated over years. The website loads tracking scripts, the contact form requests more data than necessary, and nobody knows exactly what information is flowing into the CRM or a newsletter tool. This is precisely where Privacy by Design brings order.
Website tracking is also important. The EDPS addresses this. CookiesCookies Simply explained: Cookies These are small text files that a browser stores for a website to manage sessions, preferences, or measurement data. Browser-Cookies or rather... Click to learn moreSimilar tracking technologies and third-party requests are explicitly considered indicators of data processing relevant to data protection on websites. For SMEs, this means: Tracking It is never just a marketing question, but always also a data protection question.
5-point checklist for SMEs
- Check website: Remove anything that doesn't serve a clear business purpose. Every plugin, embedded video, and external font can trigger additional data flows.
- Streamline forms: A Contact form Often, all that's needed is name, email address, and message. Phone number, date of birth, or company name are only useful if the specific purpose truly requires them.
- Limit tracking: use Conversion tracking Only as far as is truly necessary for the decision. Check whether aggregated measurement is sufficient before activating personalized analysis.
- Select third-party providers carefully: For newsletter, CRM, appointment booking or analytics tools, you need to consider technical security measures, storage location, permissions and Data processing think ahead.
- Clarify internal processes: Define who is allowed to see which data, how long data is stored, and when data is deleted or anonymized. Good. technical and organizational measures It doesn't begin in the server room, but in everyday life.
Typical examples from SME projects
Contact form: If a form is intended for a general inquiry, a few fields are sufficient. An optional phone number field can be useful, but a mandatory date of birth field is almost never necessary. Privacy by Design here means: fewer fields, a clear statement of purpose, secure transmission, and no unnecessary sharing with third-party tools.
Newsletter: The NewsletterA "newsletter" is essentially nothing more than a digital message that is regularly sent to subscribers. Imagine you have a favorite magazine... Click to learn more This requires separate consent and a verifiable registration process, such as double opt-in. Privacy by default means that no advertising consent is pre-selected and only the data actually needed for sending the emails is collected.
Appointment booking: Many booking tools request more information than is necessary for an initial consultation. Check whether your address, company name, revenue bracket, or other mandatory fields are truly required. If an external provider is involved, review their data processing agreement.
CRM and marketing automation: Sales and tracking systems are only helpful if they are properly configured. Otherwise, duplicate data records, overly broad access rights, and unnecessary data collections will result. This is especially true when... Marketing automation tools It is worth asking which data points are truly necessary for business purposes.
First-party data: Many SMEs can use their own, cleanly collected data. first-party data It's better to work with your own system than with ever-increasing third-party tracking. This is often not only more privacy-friendly, but also strategically clearer.
FAQ: The most important questions about Privacy by Design
Is Privacy by Design mandatory?
Yes. The legal core lies in Art. 25 DSGVOThis requires data protection through technical design and data protection-friendly default settings. This obligation does not mean that every SME needs a complex corporate system, but rather that processes, websites, and tools must be designed in a transparent, data-minimizing, and risk-aware manner.
Does this also apply to small businesses?
Yes, even small businesses must consider privacy by design. The scope of the measures depends on the risk, purpose, extent of processing, and means used. However, the basic logic remains the same: only necessary data, clear purposes, appropriate default settings, and controlled access.
Is a cookie banner sufficient?
No. A banner is just one component and doesn't replace proper system design. If your website loads an unnecessarily large number of scripts, forms request too much data, or providers are integrated without proper vetting, a banner alone won't solve the problem.
What is the difference to IT security?
IT securityCybersecurity protects digital systems, networks, devices, and data from attacks, misuse, failures, and data loss. For SMEs, cybersecurity is not a luxury and not solely an IT issue... Click to learn more It protects systems from attacks, failures, and unauthorized access. Privacy by Design goes further: In addition to security, it focuses on data minimization, purpose limitation, transparency, access restriction, and fair default settings for the data subject.
When do you need external advice?
External support is worthwhile as soon as multiple tools interact, personal data flows between websites, CRM systems, newsletters, or appointment booking systems, or when responsibilities are unclear. Good consulting often saves more money than it costs by preventing later modifications, unnecessary tools, and operational uncertainty.
Sources
- GDPR, Article 25 — gdpr-info.eu (2016)
- European Data Protection Board, Data protection by design & by default: When to act and what to do — edpb.europa.eu (2026)
- Global Privacy and Security by Design Centre, The Seven Foundational Principles — gpsbydesigncentre.com (2021)
- European Data Protection Supervisor, Data Protection and Privacy Tools — edps.europa.eu (2018)