Privacy by Design

Definition

An approach to systems engineering and product development that embeds data protection principles into the design and architecture of IT systems and business practices from the outset, rather than retrofitting them. Privacy by Design is codified as a legal requirement under GDPR Article 25 and encompasses data minimisation, pseudonymisation, and purpose limitation as default settings.

Complementary Terms

Concepts that frequently appear alongside Privacy by Design in practice.

Design Capital

The value created through investment in design activities including product design, UX design, service design, and architectural design. Design capital improves customer experience, brand perception, and product-market fit, and is a key intangible asset category in the Opagio framework.

MLOps

A set of practices combining machine learning, DevOps, and data engineering to standardise and streamline the end-to-end lifecycle of machine learning models, from development through deployment to monitoring. MLOps encompasses version control for models and data, automated testing, continuous integration and deployment, and model performance monitoring in production.

Data Protection Impact Assessment

A structured process required under GDPR Article 35 to identify, assess, and mitigate privacy risks arising from data processing activities that are likely to result in high risk to individuals. DPIAs are mandatory before deploying new technologies, large-scale profiling, or processing sensitive personal data, and must document the necessity, proportionality, and safeguards of the proposed processing.

Data Sovereignty

The principle that data is subject to the laws and governance structures of the country in which it is collected or stored. Data sovereignty requirements affect cloud computing architecture, cross-border data transfers, and vendor selection, particularly in light of GDPR restrictions on transfers to countries without adequate data protection standards.

Interoperability

The ability of different information technology systems, software applications, and data formats to communicate, exchange data, and use the information that has been exchanged effectively. Interoperability is a critical design requirement in open banking, healthcare IT, and enterprise software, and is increasingly mandated by regulation.

Generative AI

A category of artificial intelligence systems capable of creating new content — including text, images, code, music, and video — based on patterns learned from training data. Generative AI is transforming content production, product design, and software development, raising novel questions about intellectual property ownership and the valuation of AI-generated outputs.

Data Mesh

A decentralised data architecture paradigm that treats data as a product owned by domain-specific teams rather than centralising all data management in a single platform team. Data mesh is built on four principles: domain ownership, data as a product, self-serve data infrastructure, and federated computational governance.

Creative Capital

The intangible value derived from artistic, design, and creative capabilities within an organisation. Creative capital encompasses brand aesthetics, content libraries, product design expertise, and cultural assets that differentiate a business and drive customer engagement.

Put this knowledge to work

Use Opagio's free tools to measure and grow the intangible assets that drive your business value.