Data ProtectionPrivacy Engineering Best Practices: How to Build Privacy Into Systems by Design
Your product team is three days from shipping a feature that processes location history, inferred demographics, and browsing behaviour to power personalised recommendations. Legal reviews the privacy notice. Security scans for vulnerabilities. Nobody asks the fundamental question: should this system collect all of this in the first place, and if it does, what happens to the data when a user asks for it to be deleted?










