Data Protection by Design and by Default (DPbD)

The Data Protection by Design guideline that JPDP released on 30 April 2026 asks organisations to stop fixing privacy after launch and build it into systems, products and processes from the start. The guideline is deliberately non-prescriptive. It sets four principles, being proactive about risk with minimum data collection by default, protecting data end to end from design to decommissioning, being transparent enough to demonstrate what you say you do, and designing around the interests of the individual, and leaves the method to you. That flexibility is also the difficulty: a policy that says "we practise privacy by design" proves nothing, and the retrofit cost of getting it wrong is usually far higher than the original build.

This two-day course turns the four principles into things teams can actually do and evidence: privacy requirements written as acceptance criteria, default settings that minimise data, design review gates, retention built into the architecture, and vendor contracts that carry the same standard. It is for DPOs, product managers, engineers, architects, procurement and legal, ideally attending together. It works alongside Data Protection Impact Assessment, which assesses risk, and ISO 27701, which manages privacy as a system.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

Day 1, 9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

Day 1, 9:15 AM - 10:15 AM

What the DPbD Guideline Asks For

The guideline's status and scope, the four principles, and how data protection by design relates to the PDPA's Security, Retention and Data Integrity principles and to the DPIA and ADMP guidelines released the same day. Why a non-prescriptive guideline still raises the bar on what you can explain after an incident.

03

Day 1, 10:15 AM - 10:30 AM

Break

04

Day 1, 10:30 AM - 11:30 AM

Principle One: Proactive, and Private by Default

Collecting only what the purpose needs, optional fields that are genuinely optional, privacy-protective default settings, and resisting "collect it in case". Before-and-after examples of sign-up forms, apps and CRM configurations.

05

Day 1, 11:30 AM - 12:30 PM

Principle Two: End-to-End Protection Across the Lifecycle

Protection from design through collection, use, sharing, archiving and decommissioning. Retention rules built into systems rather than left to manual clean-ups, secure deletion, and what happens to data when a system is retired.

06

Day 1, 12:30 PM - 1:30 PM

Lunch

07

Day 1, 1:30 PM - 3:15 PM

Principle Three: Transparency You Can Demonstrate

Notices that match reality, records of design decisions, and being able to show a regulator or customer that the system does what the policy says. Keeping documentation in step with releases.

08

Day 1, 3:15 PM - 3:30 PM

Break

09

Day 1, 3:30 PM - 4:45 PM

Principle Four: Designing Around the Individual

User-centric design, meaningful choices, easy exercise of rights such as access and correction, and avoiding dark patterns that steer people into sharing more than they intended.

10

Day 1, 4:45 PM - 5:00 PM

Day 1 Close

Recap and what to review before day two.

11

Day 2, 9:00 AM - 9:15 AM

Day 1 Review

Recap of day one and the questions it left open.

12

Day 2, 9:15 AM - 10:15 AM

Privacy Requirements in Product and Engineering

Writing privacy requirements as user stories and acceptance criteria, threat and privacy modelling in design, architecture patterns such as pseudonymisation, tokenisation and segregation, and privacy checks in testing and release.

13

Day 2, 10:15 AM - 10:30 AM

Break

14

Day 2, 10:30 AM - 12:30 PM

Procurement, Vendors and Third-Party Components

Carrying DPbD into procurement: requirements in tenders, evaluating SaaS and AI tools, contract terms, default configurations of bought-in systems, and reviewing third-party SDKs and trackers in apps and websites.

15

Day 2, 12:30 PM - 1:30 PM

Lunch

16

Day 2, 1:30 PM - 3:15 PM

Design Gates, Metrics and Evidence

Where to place review gates so they help rather than block delivery, who signs off, and what evidence each gate produces. Metrics that show the programme working, and reporting to management.

17

Day 2, 3:15 PM - 3:30 PM

Break

18

Day 2, 3:30 PM - 4:45 PM

Workshop: Design Review of a Real Feature

Cross-functional teams take a proposed feature through a DPbD review, rewrite its data collection and defaults, and produce the design record and vendor requirements that go with it.

19

Day 2, 4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Explain the four principles of the JPDP Data Protection by Design guideline and what each requires in practice
  • Set privacy-protective defaults and minimise data collection without breaking the product
  • Build retention and deletion into systems across the full data lifecycle
  • Write privacy requirements into user stories, architecture and testing
  • Carry DPbD requirements into procurement and vendor contracts
  • Operate design review gates that produce evidence a regulator would accept

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate. For DPOs, product managers, engineers and architects, UX designers, procurement, legal and IT security. Basic PDPA knowledge assumed.

Duration   2 Days (16 Hours)  |  9:00 AM to 5:00 PM daily

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A DPbD design review record for a supplied or participant feature, plus a written knowledge check

Certificate   Certificate of Completion issued to all participants upon full attendance

Enquiries   Contact us to register or discuss scheduling

Frequently Asked Questions

Yes. Data Protection by Design and by Default (DPbD) is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

Data Protection by Design and by Default (DPbD) runs for 2 days (16 hours) | 9:00 AM to 5:00 PM daily. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Intermediate. For DPOs, product managers, engineers and architects, UX designers, procurement, legal and IT security. Basic PDPA knowledge assumed. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.