The Blue Book of UX Directives
7. Trust, Safety & Responsibility

5. Privacy

What happens to personal information.

First, ask yourself

“Do users of your system know and control what personal information it collects, keeps, and shares?”

Mission statement

Ensure users keep control of personal information by collecting the minimum, explaining its use, and honoring their choices.

Key heuristics Privacy

  1. Collection must be limited to what the stated purpose requires.
  2. The purpose of every collection must be stated at the point of collection.
  3. Defaults must favor privacy.
  4. Users must be able to see what is held about them.
  5. Users must be able to correct, export, and delete their information.
  6. Sharing with third parties must require explicit, specific consent.
  7. Retention must be limited and stated.
  8. Privacy controls must be reachable where the related data is used.
  9. Privacy choices must persist across sessions, devices, and updates.

Executive brief

The system must treat personal information as the user’s, held in trust for a stated purpose.

Core questions Privacy

“What personal information does the system collect, and why?”

“Can users see, change, and remove it?”

Focus areas

Minimization-first

“Is every field needed for the stated purpose?”

“What could be collected less precisely?”

Visibility-aware

“Can users see everything held about them?”

“Is the purpose stated where data is collected?”

Control-aware

“Can users export or delete their data without contacting support?”

“Are privacy settings near the features they affect?”

AI-aware

“Is personal information used to train models?”

“Can users exclude their data from learning?”

UX directives Privacy

Directive75/01

Collect the minimum.

Request only the personal information the stated purpose requires.

Directive75/02

State purpose at collection.

Explain why information is needed where and when it is requested.

Directive75/03

Default to privacy.

Set the most protective option as the default.

Directive75/04

Make held data visible.

Let users see all personal information the system holds about them.

Directive75/05

Enable correction, export, and deletion.

Provide direct controls without requiring support contact.

Directive75/06

Require specific consent for sharing.

Do not share personal information with third parties under general or implied consent.

Directive75/07

Limit and state retention.

Keep personal information only as long as stated, then remove it.

Directive75/08

Place privacy controls in context.

Offer privacy choices where the related data is used.

Directive75/09

Preserve privacy choices.

Ensure settings persist across sessions, devices, and updates.

Executive summary

  • Privacy is the user’s control over personal information, not a policy document.
  • It limits what is collected to what a stated purpose requires.
  • The system must default to protection and state purpose at the point of collection.
  • Users must be able to see, correct, export, and delete what is held about them.
  • Sharing and retention must be specific, consented, and limited.
  • Privacy succeeds when users know what the system holds and why, and can change it at any time.

Success indicators

  • Only necessary personal information is requested.
  • The purpose of collection is stated where data is entered.
  • Protective options are the default.
  • Users can view, export, and delete their data directly.
  • Privacy choices persist across sessions and updates.

One-line summary

Before users can share personal information, they must know it remains theirs.