It includes expectations, autonomy, transparency, fairness, access and participation, and protection from harmful or unexpected data actions. Privacy is not synonymous with secrecy: publicly available or securely stored data can still be processed in intrusive, unfair, or incompatible ways.
Privacy work translates these concerns into governance, product decisions, operational controls, and methods for identifying and reducing risks to individuals. Applicable rights and duties vary by jurisdiction and relationship, so general practice must be paired with qualified legal analysis.
Key points
PurposeDefine the intended outcome, assess necessity and proportionality, limit collection and reuse, and identify people who may be affected even when they are not direct users.
Transparency and choiceProvide meaningful information about data practices, enable appropriate choices and requests, and avoid interfaces or policies that obscure material consequences.
Context-aware designMinimize data, separate incompatible uses, constrain access and retention, evaluate linkability and inference, and test how systems behave across the full lifecycle.
Important limitationSecurity and regulatory compliance can support privacy but do not prove it. A secure system may enable inappropriate surveillance or inference, while consent or de-identification does not eliminate every privacy risk.