---
title: "Privacy-by-Design Becomes an ISO Standard: a New Driver for Data-Centric Security"
description: ISO 31700 is based on privacy-by-design principles first developed in the 90s and could help provide practical steps to implement these best practices.
image: https://insights.comforte.com/hubfs/blog%20header%20image%20pci%20dss%204%20point%200-2.jpeg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![](https://insights.comforte.com/hubfs/blog%20header%20image%20pci%20dss%204%20point%200-2.jpeg)](https://insights.comforte.com/privacy-by-design-becomes-an-iso-standard-a-new-driver-for-data-centric-security)

[Thomas Stoesser](https://insights.comforte.com/author/thomas-stoesser) l Feb 16, 2023 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance)

# Privacy-by-Design Becomes an ISO Standard: a New Driver for Data-Centric Security

Consumer trust in online services is a growing preoccupation of today’s boardrooms. That’s because customers are increasingly prepared to walk if they don’t like what they see. In fact, 71% of consumers [told PwC](https://www.pwc.com/us/en/services/consulting/library/consumer-intelligence-series/trust-new-business-currency.html) last year that they’re unlikely to buy from a company that loses their trust. This might happen following a serious data breach, or other privacy-related incident. [Separate research](https://www.malwarebytes.com/blog/news/2022/03/data-breaches-leave-customers-very-shaky-report-says) shows that 68% would be put off buying online from a company with inadequate data security – rising even higher (75%) for firms which have breached customer data in the past.

The good news for organizations that want to burnish their privacy credentials and improve best practice is that a new ISO standard has just been published. [ISO 31700](https://www.iso.org/obp/ui/#iso:std:iso:31700:-1:ed-1:v1:en) is based on privacy-by-design principles first developed in the 1990s, and could help by providing practical steps to implement these best practices.

## The privacy-by-design journey

Privacy by design was developed by Ontario Information and Privacy Commissioner Anne Cavoukian with the tenets that privacy can’t be guaranteed solely via compliance with regulations – that it must be the default setting for organizations and built into everything they do by default. It was published as a framework in 2009 and adopted [eventually by the GDPR.](https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-by-design-and-default/#:~:text=External%20link-,What%20is%20data%20protection%20by%20design%3F,and%20then%20throughout%20the%20lifecycle.)

The new ISO standard adds plenty more detail to the approach and can be seen as a way to help organizations of all sizes to “operationalize” privacy by design. In so doing, they should become more resilient to possible incidents and may find compliance with GPDR and other laws easier.

Although ISO 31700 has 30 requirements, the original privacy-by-design document contains just [seven principles](https://www.ipc.on.ca/wp-content/uploads/resources/7foundationalprinciples.pdf), which summarize the approach fairly neatly:

- **Be proactive and preventative, not reactive and remedial:** i.e. anticipate and prevent privacy invasive events before they happen
- **Privacy must be the default setting:** personal data is automatically protected in any given IT system or business practice, with no action required by the user
- **Privacy is embedded into design** as an essential component of core functionality, rather than a bolt on
- **Implement in a positive sum, win-win manner** and not via unnecessary trade-offs
- **Deliver end-to-end security** from start to finish, for full lifecycle protection
- **Visibility and transparency** is a must for users and providers alike
- **User-centric privacy** via strong privacy defaults, appropriate notice, and empowering user-friendly options

## Why data-centric security matters

It becomes obvious reading the above that to implement privacy by design, organizations need a way to ensure all customer data they process, via any service or back-end system, must be protected by default throughout its entire lifecycle. This is exactly the promise of [comforte’s data-centric security](https://www.comforte.com/data-security) approach.

Our Data Security Platform automatically and continuously discovers and classifies data before seamlessly applying strong protection in line with corporate policy. Format-preserving techniques for data protection, such as tokenization, mean data can still be used in analytics and other business use cases, without compromising on privacy-by-design principles.

According to the ISO, the benefits of implementing its new privacy-by-design standard are:

**Earn consumer trust and satisfy demands** for robust privacy and data protection.

**Institutionalize robust privacy norms** throughout the ecosystem – including privacy protection and data handling practices – ensuring decisions concerning consumer privacy needs will be more consistent and systematic.

**Benefit from a more holistic and integrated approach** by ensuring privacy best practices apply to the broader information ecosystems in which technologies and organizations operate and function.

**Support an iterative approach to product development**, so that privacy enhancements can be deployed long after the initial design phase.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/privacy-by-design-becomes-an-iso-standard-a-new-driver-for-data-centric-security&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/privacy-by-design-becomes-an-iso-standard-a-new-driver-for-data-centric-security&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/privacy-by-design-becomes-an-iso-standard-a-new-driver-for-data-centric-security&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/privacy-by-design-becomes-an-iso-standard-a-new-driver-for-data-centric-security&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/privacy-by-design-becomes-an-iso-standard-a-new-driver-for-data-centric-security&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Want to learn more?

Click the button below to download our data security platform solution brief:

[![Download Solution Brief](https://no-cache.hubspot.com/cta/default/4026697/7962e9ff-2c50-4207-910f-fc5fd97083e7.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/7962e9ff-2c50-4207-910f-fc5fd97083e7)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>