Data protection is one of the key challenges at Spaycial. We have already mentioned the main texts in this direction, with PSD2 and GDPR. These new regulations are progressing at the same pace as the use of digital technology in the world, and particularly in Europe. Privacy by design is part of these new obligations, in terms of product and service design for brands. We explain what this concept is and how we apply it, with Nurgül Sivasli, our Data Protection Officer (DPO).
It is one of the new principles introduced by the GDPR regulation and is part of the compliance efforts and obligations of companies. Every action of a company must take into account the protection of the shopper's personal data, and this from the conception of a product or a service. This is an additional security for the shopper benefiting from personalized offers thanks to payment data, as Spaycial can propose.
By using privacy by design, the DPO accompanies and advises his/her company in order to integrate data protection into all operational processes, and more particularly into the development processes of products and services, as early as possible, from the start of the project until the final design of the product. Thereafter, the DPO ensures that this protection cycle is maintained on a continuous basis.
Nurgül Sivaslı explains: "At Spaycial, before any launch of a new product or service, such as our "Shopping scoring" service, as DPO I am consulted by the technical teams in order to ensure the lawfulness of the processing and in particular the choice of the legal basis: consent, contract or legitimate interest. Following the principle of 'privacy by design' allows us to anticipate the obligations of transparency and the rights of the users, especially since the education of the consumer is essential and represents the real challenge in the field of payment. Finally, the implementation of this principle ensures that only adequate, relevant and strictly necessary data is processed.”
Privacy by design is accompanied by privacy by default. These principles are obviously illustrated by the integration of state-of-the-art security standards (RTS rules and strong authentication) and by the governance of personal data security in all our projects and decisions.
There are many core principles of privacy by design that, if followed, will make payment data protection compliance efforts a reality. Here are the 7 principles of privacy by design, as applied by payment data specialists.