Privacy by design for websites and applications
Document what you collect, why, who receives it and how long it is retained, including analytics, email and hosting providers. Applicable laws depend on the business, users…
Map data before building
Document what you collect, why, who receives it and how long it is retained, including analytics, email and hosting providers. Applicable laws depend on the business, users and processing context.
Minimise collection and separate purposes
An enquiry form should not request unnecessary sensitive data. Separate project communication from marketing, and make cookie choices and consent withdrawal work in practice.
Access, security and requests
Use role-based access, keep secrets out of browsers and avoid personal data in logs. Assign responsibility for access, correction or deletion requests and incident handling.
Review the actual context
This is an engineering checklist, not certification of PDPA or GDPR compliance. Have the responsible legal adviser review processing grounds, retention and provider agreements before launch.
Sources
Have a project to discuss?
Share the context and goal. We’ll help identify a practical first scope.
Explore the related serviceLet’s talk