Privacy is built into new systems and processes from the start
Requiring privacy questions to be answered before any new system or vendor goes live builds this control's protections into projects from the start rather than after launch.
This policy facet requires privacy questions, data minimization, retention, lawful basis, to be answered before any new system touches personal data, one design principle A.8.27 covers.
https://sekit.ai/api/mcp/crosswalk