Building data-protection safeguards into the system: Which action best reflects that principle at the design
Privacy by design means embedding data-protection safeguards into the architecture from the outset and by default, not adding controls after launch.
The question
A team applies the principle of privacy by design when building a new AI feature. Which action best reflects that principle at the design stage?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Adding a written privacy notice to the application only after the new feature has fully launched.Plausible but wrong: a post-launch notice is a late, add-on transparency step, not the proactive design-stage embedding that privacy by design requires.
- Running a comprehensive security audit once the system is already live in production.Plausible but wrong: a security audit after deployment is a valuable check but does not embody designing in privacy from the start.
- Building data-protection safeguards into the system architecture by default from the start. ✓Correct: privacy by design means embedding data-protection measures into the system's architecture from the outset and by default, rather than bolting them on later.
- Collecting extra personal data upfront to avoid having to re-collect it again later.Plausible but wrong: collecting surplus data contradicts both privacy by design and data minimization.
The trap
Believing a post-launch privacy notice or security audit satisfies privacy by design, when the principle requires building protections in from the outset. How to remember it
Privacy by design means embedding data-protection safeguards into the architecture from the outset and by default, not adding controls after launch.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- The controller's legitimate interests: Which of the following is a recognized lawful basis under GDPR? →
- Complete a DPIA: Acting as the GDPR data controller, which combination of measures must be in place before →
- Biometric templates used to uniquely identify staff are: Under GDPR, which analysis best fits processing this →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.