Privacy by Design in Practice – icoso consulting S.L.

Insights

Privacy by Design in Practice

Insight · Daniel Osorio Fernandez, icoso consulting S.L.

Data protection appears in every project deck — it is lived in the architecture. Building our own end-to-end encrypted health app taught us lessons that transfer directly to enterprise IT.

Context: Article 25 GDPR requires data protection by design and by default. Health data is a special category under Article 9. Our own product Luna encrypts sensitive data client-side with AES-256 — the operator itself cannot read it (zero-knowledge architecture).

Data protection is an architecture decision

The most important privacy properties of a system are fixed in its first weeks: where are keys created and who holds them? What does the backend get to see at all? Which data leaves the EU — and why? Raise these questions only in the privacy review before go-live and you can usually just document the answers, no longer change them. Retrofitting is an architecture rebuild, not a patch.

Five transferable lessons

  • Zero knowledge wherever possible: what the operator could never read, it can neither lose nor be forced to hand over. Client-side encryption shrinks risk and liability alike.
  • Connect AI on a data diet: personalisation does not need raw data. Anonymised, categorical signals to EU-hosted models achieve a great deal — and keep the DPIA lean.
  • Actively manage the processor chain: behind every cloud solution stand sub-processors. Each needs a vetted DPA — and the list changes, so it must be managed, not filed once.
  • Documentation as a living system: DPIA, records of processing and TOMs are best written alongside the code. Write them afterwards and you document a different system than the one you built.
  • Test data is production risk: synthetic data and clean environment separation from day one — the most common privacy gap in projects is real data in test and development systems.

What this means for enterprise IT

The same questions decide audit-readiness in every S/4HANA migration, banking project and cloud adoption: data minimisation in interfaces, anonymisation concepts for test data, reliable records of processing and evidence that supervisors and auditors can read without translation. Privacy by design is not a product feature — it is a way of working.

Bottom line

You understand data protection differently when you are the one liable: more precisely, more pragmatically and earlier in the project. That is exactly the experience we bring into client engagements.

More on building custom solutions: Custom Software & App Development — or contact us directly.

Let's talk about your project.

Straightforward and personal — we'll get back to you quickly.

Get in touch

Or directly: +34 619 13 73 23 · info@icoso.es