Data Protection by Design and by Default (DPbD)
The Data Protection by Design guideline that JPDP released on 30 April 2026 asks organisations to stop fixing privacy after launch and build it into systems, products and processes from the start. The guideline is deliberately non-prescriptive. It sets four principles, being proactive about risk with minimum data collection by default, protecting data end to end from design to decommissioning, being transparent enough to demonstrate what you say you do, and designing around the interests of the individual, and leaves the method to you. That flexibility is also the difficulty: a policy that says "we practise privacy by design" proves nothing, and the retrofit cost of getting it wrong is usually far higher than the original build.
This two-day course turns the four principles into things teams can actually do and evidence: privacy requirements written as acceptance criteria, default settings that minimise data, design review gates, retention built into the architecture, and vendor contracts that carry the same standard. It is for DPOs, product managers, engineers, architects, procurement and legal, ideally attending together. It works alongside Data Protection Impact Assessment, which assesses risk, and ISO 27701, which manages privacy as a system.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
Day 1, 9:15 AM - 10:15 AM
What the DPbD Guideline Asks For
The guideline's status and scope, the four principles, and how data protection by design relates to the PDPA's Security, Retention and Data Integrity principles and to the DPIA and ADMP guidelines released the same day. Why a non-prescriptive guideline still raises the bar on what you can explain after an incident.
Day 1, 10:15 AM - 10:30 AM
Break
Day 1, 10:30 AM - 11:30 AM
Principle One: Proactive, and Private by Default
Collecting only what the purpose needs, optional fields that are genuinely optional, privacy-protective default settings, and resisting "collect it in case". Before-and-after examples of sign-up forms, apps and CRM configurations.
Day 1, 11:30 AM - 12:30 PM
Principle Two: End-to-End Protection Across the Lifecycle
Protection from design through collection, use, sharing, archiving and decommissioning. Retention rules built into systems rather than left to manual clean-ups, secure deletion, and what happens to data when a system is retired.
Day 1, 12:30 PM - 1:30 PM
Lunch
Day 1, 1:30 PM - 3:15 PM
Principle Three: Transparency You Can Demonstrate
Notices that match reality, records of design decisions, and being able to show a regulator or customer that the system does what the policy says. Keeping documentation in step with releases.
Day 1, 3:15 PM - 3:30 PM
Break
Day 1, 3:30 PM - 4:45 PM
Principle Four: Designing Around the Individual
User-centric design, meaningful choices, easy exercise of rights such as access and correction, and avoiding dark patterns that steer people into sharing more than they intended.
Day 1, 4:45 PM - 5:00 PM
Day 1 Close
Recap and what to review before day two.
Day 2, 9:00 AM - 9:15 AM
Day 1 Review
Recap of day one and the questions it left open.
Day 2, 9:15 AM - 10:15 AM
Privacy Requirements in Product and Engineering
Writing privacy requirements as user stories and acceptance criteria, threat and privacy modelling in design, architecture patterns such as pseudonymisation, tokenisation and segregation, and privacy checks in testing and release.
Day 2, 10:15 AM - 10:30 AM
Break
Day 2, 10:30 AM - 12:30 PM
Procurement, Vendors and Third-Party Components
Carrying DPbD into procurement: requirements in tenders, evaluating SaaS and AI tools, contract terms, default configurations of bought-in systems, and reviewing third-party SDKs and trackers in apps and websites.
Day 2, 12:30 PM - 1:30 PM
Lunch
Day 2, 1:30 PM - 3:15 PM
Design Gates, Metrics and Evidence
Where to place review gates so they help rather than block delivery, who signs off, and what evidence each gate produces. Metrics that show the programme working, and reporting to management.
Day 2, 3:15 PM - 3:30 PM
Break
Day 2, 3:30 PM - 4:45 PM
Workshop: Design Review of a Real Feature
Cross-functional teams take a proposed feature through a DPbD review, rewrite its data collection and defaults, and produce the design record and vendor requirements that go with it.
Day 2, 4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Explain the four principles of the JPDP Data Protection by Design guideline and what each requires in practice
- Set privacy-protective defaults and minimise data collection without breaking the product
- Build retention and deletion into systems across the full data lifecycle
- Write privacy requirements into user stories, architecture and testing
- Carry DPbD requirements into procurement and vendor contracts
- Operate design review gates that produce evidence a regulator would accept
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate. For DPOs, product managers, engineers and architects, UX designers, procurement, legal and IT security. Basic PDPA knowledge assumed.
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A DPbD design review record for a supplied or participant feature, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance