Everything so far has been about meeting the DPDP Act’s requirements. This is about organisations that go a step further — starting with what “privacy by design” actually means.
Bolted on
- Privacy review happens after a product is basically finished
- A consent banner gets added to satisfy a legal checklist
- Fixing a privacy gap means reworking shipped code
Built in
- Privacy is a question asked at the design stage, before anything is built
- Data collection is minimised from the start, so less consent is even needed
- Fixing a privacy gap means adjusting a design that hasn't shipped yet
Privacy by design isn’t a DPDP-specific idea — it’s a well-established principle in data protection thinking generally, and it shows up in other major privacy laws too. What it means practically is simple: it’s dramatically cheaper and safer to design for privacy before a system exists than to retrofit it into one that’s already live.
Privacy by design isn’t extra work. It’s the same work, done earlier, when it’s cheaper to do.