Risk and controls
Conduct a privacy by design review
Review a proposed system, product or material change before implementation, and turn the requirements into controlled actions, design constraints or measures.
A product team proposing a new referral feature that shares contact details between users needs the privacy requirements settled before a line of code is written, not after launch. A privacy by design review is where those requirements are captured and turned into obligations someone owns.
This is exercised through the audit and review register, kept apart from the activity it concerns so the review can happen even before the activity itself has been fully specified.
The proof is that every requirement identified leaves the review as its own record with an owner, and that the review is linked back to the activity once it exists.
- Regulation
- Article 25
- Registers
- Audit and review · Processing activity · DPIA · Privacy action · Measure

The steps
- 01Open the Audit and review register and use the plus button beside the register title to create the review.
- 02Name the proposal under review on the Details tab.
- 03Record each requirement identified in the review as a separate line.
- 04Open the Privacy actions register and use the plus button beside the register title to raise an action for each requirement, or create a measure where the requirement is a standing control.
- 05Open the Linked records band and use "Link a record" to attach the review to the activity it concerns.

Accepted when
- Every requirement leaves the review as a record with an owner.
- The review is linked to the activity it concerns.