Data protection and privacy consideration must be included by default at the design stage and throughout the product development lifecycle. In addition, design documentation should clearly describe how data is protected.
Develop systems, products, and business practices based upon a principle of security by design and industry best practices.