What happens to personal information.
First, ask yourself
“Do users of your system know and control what personal information it collects, keeps, and shares?”
Mission statement
🫡Ensure users keep control of personal information by collecting the minimum, explaining its use, and honoring their choices.
Key heuristics → Privacy
🚀- Collection must be limited to what the stated purpose requires.
- The purpose of every collection must be stated at the point of collection.
- Defaults must favor privacy.
- Users must be able to see what is held about them.
- Users must be able to correct, export, and delete their information.
- Sharing with third parties must require explicit, specific consent.
- Retention must be limited and stated.
- Privacy controls must be reachable where the related data is used.
- Privacy choices must persist across sessions, devices, and updates.
Executive brief
☝️The system must treat personal information as the user’s, held in trust for a stated purpose.
Core questions → Privacy
🤔“What personal information does the system collect, and why?”
“Can users see, change, and remove it?”
Focus areas
Minimization-first
“Is every field needed for the stated purpose?”
“What could be collected less precisely?”
Visibility-aware
“Can users see everything held about them?”
“Is the purpose stated where data is collected?”
Control-aware
“Can users export or delete their data without contacting support?”
“Are privacy settings near the features they affect?”
AI-aware
“Is personal information used to train models?”
“Can users exclude their data from learning?”
🧬 UX directives → Privacy
Directive75/01
Collect the minimum.
Request only the personal information the stated purpose requires.
Directive75/02
State purpose at collection.
Explain why information is needed where and when it is requested.
Directive75/03
Default to privacy.
Set the most protective option as the default.
Directive75/04
Make held data visible.
Let users see all personal information the system holds about them.
Directive75/05
Enable correction, export, and deletion.
Provide direct controls without requiring support contact.
Directive75/06
Require specific consent for sharing.
Do not share personal information with third parties under general or implied consent.
Directive75/07
Limit and state retention.
Keep personal information only as long as stated, then remove it.
Directive75/08
Place privacy controls in context.
Offer privacy choices where the related data is used.
Directive75/09
Preserve privacy choices.
Ensure settings persist across sessions, devices, and updates.
Executive summary
⚡- Privacy is the user’s control over personal information, not a policy document.
- It limits what is collected to what a stated purpose requires.
- The system must default to protection and state purpose at the point of collection.
- Users must be able to see, correct, export, and delete what is held about them.
- Sharing and retention must be specific, consented, and limited.
- Privacy succeeds when users know what the system holds and why, and can change it at any time.
Success indicators
😎- Only necessary personal information is requested.
- The purpose of collection is stated where data is entered.
- Protective options are the default.
- Users can view, export, and delete their data directly.
- Privacy choices persist across sessions and updates.
One-line summary
☝️Before users can share personal information, they must know it remains theirs.