Privacy by Design Scorer
Score a system or feature against data protection by design and by default, covering defaults, technical measures, transparency and lifecycle, with the essential requirements that cannot be traded away.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
By design means before the design is fixed
Article 25 requires measures at the time of determining the means of processing, not at launch. That timing is the whole substance of the obligation: a privacy review that happens once the schema is settled and the integrations are built can only recommend changes that are now expensive, which is precisely why such recommendations get overruled. A review at design stage costs a conversation; the same review after build costs a migration, and the difference decides whether it happens.
By default is a separate and stricter requirement
Article 25(2) is not a restatement of the first paragraph. It requires that, by default, only personal data necessary for each specific purpose is processed, and that data is not made accessible to an indefinite number of people without the individual acting. A system with excellent privacy controls that ships with all of them switched off satisfies the first paragraph and fails the second, and that configuration is common because defaults are usually chosen for engagement rather than for compliance.
Privacy threat modelling asks a different question
Security threat modelling asks who could break in and what they would reach. Privacy threat modelling asks what the system does to the people in it when it works exactly as designed: what it infers, who can see it, what follows someone who leaves. A system can be secure against every attacker and still be the problem, and the two exercises produce different findings because they start from different questions.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
When should the assessment happen?
At the time the means of processing are determined, which is before the schema is fixed. A review after build can only recommend expensive changes, which is why they get overruled.
What does "by default" add?
Article 25(2) is a separate requirement: only data necessary for each purpose is processed by default, and data is not made accessible to an indefinite number of people without the individual acting. A system whose privacy controls all ship switched off fails it.
How is privacy threat modelling different from security threat modelling?
Security asks who could break in. Privacy asks what the system does to the people in it when it works exactly as designed. A system can be secure against every attacker and still be the problem.
Why is withdrawing consent treated as essential?
Article 7(3) requires it to be as easy as giving consent. A one-click opt-in paired with an email request to opt out is one of the easiest failures for a regulator to reproduce.
Is a high score compliance?
No. The score shows which measures are present. Whether the processing is lawful, necessary and proportionate is a separate question this cannot answer.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Tick the measures in place to score the design.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.