The Regulation introduces the concept of “privacy by design”. Pursuant to art. 23 of the Regulation, the Controller shall implement appropriate technical and organisational measures and procedures in such a way that the processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.
This principle is already in the current Directive, but it is now introduced as a specific, stand-alone concept so it is fundamental to discuss a new approach that every internal work-flow must have in the future in order to comply with Regulation principles.