IEEE 2089 Principle 4 - Data Protection by Design
Embed data protection by design and by default into services used by children, with privacy-protective defaults and data minimization
Where this comes from
Provision: Principle 4 - Data Protection by Design
Instrument: IEEE 2089-2021
Citation: IEEE 2089-2021, Standard for an Age Appropriate Digital Services Framework, Principle 4: Data Protection by Design
Text version: IEEE 2089-2021
Who it applies to
It applies when all of these are true:
- Service is likely to be accessed by children under 18
- Service collects behavioral data
- Data categories collected — any answer
- Service uses content personalization
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Default profile visibility: private (not public)
- Default data sharing: off (opt-in, not opt-out)
- Default location tracking: off
- Default contact discoverability: off
- User can change any default via settings
Questions people ask
- Does IEEE 2089 Principle 4 - Data Protection by Design apply to my service?
- It applies when Service is likely to be accessed by children under 18; Service collects behavioral data; Data categories collected — any answer; Service uses content personalization.
- From when does this apply?
- IEEE 2089 Principle 4 - Data Protection by Design applies from 10 November 2021. Its current status is: in force.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.