> For the complete documentation index, see [llms.txt](https://dpisafeguards.gitbook.io/resources-hub/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dpisafeguards.gitbook.io/resources-hub/framework/responsible-authorities/r4-technology-provider/l2-strategy-and-design.md).

# L2 - Strategy and Design

To know more about this phase of the DPI life cycle, click [here](/resources-hub/framework/responsible-authorities/r5-advocates/l2-strategy-and-design.md).

**Click on any process listed below to learn about illustrative practices that can be implemented.**

| Process                                                                                                                                                                                                                                                                                                     | Principle                                                                                                                                                | Risk                                                                                                                                                                                                                                                             |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [F2.4 Design and implement backup processes for users who lack assumed documentation](/resources-hub/framework/processes/f2.4-design-and-implement-backup-processes-for-users-who-lack-assumed-documentation.md)                                                                                            | [F2: Do not discriminate](/resources-hub/framework/principles/foundational-principles/f2-do-not-discriminate.md)                                         | [R13 Exclusion,](/resources-hub/framework/risks/risks-to-inclusion.md) [RI1 Discrimination](/resources-hub/framework/risks/risks-to-inclusion.md)                                                                                                                |
| [F4.10 Implement comprehensive reporting and accessibility protocols](/resources-hub/framework/processes/f4.10-implement-comprehensive-reporting-and-accessibility-protocols.md)                                                                                                                            | [F4: Reinforce transparency and accountability](/resources-hub/framework/principles/foundational-principles/f4-reinforce-transparency-accountability.md) | [SV1 Digital Distrust,](/resources-hub/framework/risks/risks-to-structural-vulnerabilities.md) [SV4 Technical shortcomings](/resources-hub/framework/risks/risks-to-structural-vulnerabilities.md)                                                               |
| [F6.5 Implement optional features for user control over personal data](/resources-hub/framework/processes/f6.5-implement-optional-features-for-user-control-over-personal-data.md)                                                                                                                          | [F6: Promote autonomy and agency](/resources-hub/framework/principles/foundational-principles/f6-promote-autonomy-and-agency.md)                         | [RI4 Disempowerment](/resources-hub/framework/risks/risks-to-inclusion.md), [RS1 Privacy vulnerability](/resources-hub/framework/risks/risks-to-safety.md)                                                                                                       |
| [O2.5 Implement rigorous testing protocols](/resources-hub/framework/processes/o2.5-implement-rigorous-testing-protocols.md)                                                                                                                                                                                | [O2: Evolve with evidence](/resources-hub/framework/principles/operational-principles/o2-evolve-with-evidence.md)                                        | [SV3 Weak institutions](/resources-hub/framework/risks/risks-to-structural-vulnerabilities.md)                                                                                                                                                                   |
| [O3.14 Integrate strict data minimization protocols into design](/resources-hub/framework/processes/o3.14-integrate-strict-data-minimization-protocols-into-design.md)                                                                                                                                      | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      | [RS1 Privacy vulnerability](/resources-hub/framework/risks/risks-to-safety.md)                                                                                                                                                                                   |
| [O3.15 Implement strict controls to enforce purpose limitation and restrict secondary data use.](/resources-hub/framework/processes/o3.15-implement-strict-controls-to-enforce-purpose-limitation-and-restrict-secondary-data-use.md)                                                                       | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      | [RS1 Privacy vulnerability](/resources-hub/framework/risks/risks-to-safety.md), [SV1 Digital distrust](/resources-hub/framework/risks/risks-to-structural-vulnerabilities.md)                                                                                    |
| [O3.16 Embed strong standards of privacy from the start and integrate it into design and processes](/resources-hub/framework/processes/o3.16-embed-strong-privacy-standards-from-the-start-and-integrate-these-into-design-and-processes.md)                                                                | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      |                                                                                                                                                                                                                                                                  |
| [O3.17 Ensure compliance with privacy laws and evaluate risks related to PII by conducting and publicly documenting privacy impact assessments for new or updated technologies and systems.](/resources-hub/framework/processes/o3.17-ensure-compliance-with-privacy-laws-and-evaluate-risks-around-pii.md) | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      |                                                                                                                                                                                                                                                                  |
| [O3.18 Emphasize transparency and user empowerment in managing data.](/resources-hub/framework/processes/o3.18-emphasise-transparency-and-user-empowerment-in-managing-data.md)                                                                                                                             | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      | [RI4 Disempowerment](/resources-hub/framework/risks/risks-to-inclusion.md), [RS1 Privacy vulnerabilities](/resources-hub/framework/risks/risks-to-safety.md)                                                                                                     |
| [O3.19 Develop privacy requirements and select mitigation strategies, documenting and iterating your analysis as needed.](/resources-hub/framework/processes/o3.19-develop-privacy-requirements-and-select-mitigation-strategies.md)                                                                        | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      |                                                                                                                                                                                                                                                                  |
| [O.20 Ensure unobservability of Daily User Interactions by Design](/resources-hub/framework/processes/o3.20-ensure-unobservability-of-daily-user-interactions-by-design.md)                                                                                                                                 | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      | [RS1 Privacy vulnerability](/resources-hub/framework/risks/risks-to-safety.md)                                                                                                                                                                                   |
| [O.21 Establish mechanisms to ensure a right to opt-out whenever appropriate](/resources-hub/framework/processes/o3.21-establish-mechanisms-to-ensure-a-right-to-opt-out-whenever-appropriate.md)                                                                                                           | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      | [RI4 Disempowerment](/resources-hub/framework/risks/risks-to-inclusion.md), [RS1 Privacy vulnerability](/resources-hub/framework/risks/risks-to-safety.md)                                                                                                       |
| [O3.22 Ensure linkability, unobservability, and zero-knowledge proofs are the default](/resources-hub/framework/processes/o3.22-ensure-linkability-unobservability-and-zero-knowledge-proofs-are-the-default.md)                                                                                            | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      | [RS1 Privacy vulnerability](/resources-hub/framework/risks/risks-to-safety.md), [RS2 Digital insecurity](/resources-hub/framework/risks/risks-to-safety.md)                                                                                                      |
| [O3.23 Establish Robust Data Delinking Mechanisms once the purpose of the processing of personal information has been served](/resources-hub/framework/processes/o3.23-establish-robust-data-delinking-mechanisms.md)                                                                                       | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      | [RS1 Privacy vulnerability](/resources-hub/framework/risks/risks-to-safety.md)                                                                                                                                                                                   |
| [O3.24 Make alternative mechanisms besides biometrics available for enrollment for special cases (leave nobody behind)](/resources-hub/framework/processes/o3.24-make-alternative-mechanisms-besides-biometrics-available.md)                                                                               | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      |                                                                                                                                                                                                                                                                  |
| [O3.25 Ensure that biometric authentication is not mandatory](/resources-hub/framework/processes/o3.25-ensure-that-biometric-authentication-is-not-mandatory.md)                                                                                                                                            | [O3: Ensure data privacy by design](/resources-hub/framework/principles/operational-principles/o3-ensure-data-privacy-by-design.md)                      | [RI3 Exclusion](/resources-hub/framework/risks/risks-to-inclusion.md), [RS1 Privacy vulnerability](/resources-hub/framework/risks/risks-to-safety.md), [SV4 Technical shortcomings](/resources-hub/framework/risks/risks-to-structural-vulnerabilities.md)       |
| [O4.3 Ensure secure and auditable data handling](/resources-hub/framework/processes/o4.3-ensure-secure-and-auditable-data-handling.md)                                                                                                                                                                      | [O4: Assure data security by design](/resources-hub/framework/principles/operational-principles/o4-assure-data-security-by-design.md)                    | [RS2 Digital insecurity](/resources-hub/framework/risks/risks-to-safety.md), [RS1 Privacy vulnerability](/resources-hub/framework/risks/risks-to-safety.md), [SV4 Technical shortcomings](/resources-hub/framework/risks/risks-to-structural-vulnerabilities.md) |
| [O6.6 Embed vulnerability in product design](/resources-hub/framework/processes/o6.6-embed-vulnerability-in-product-design.md)                                                                                                                                                                              | [O6: Respond to gender, ability or age](/resources-hub/framework/principles/operational-principles/o6-respond-to-gender-ability-or-age.md)               | [RI4 Disempowerment](/resources-hub/framework/risks/risks-to-inclusion.md)                                                                                                                                                                                       |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://dpisafeguards.gitbook.io/resources-hub/framework/responsible-authorities/r4-technology-provider/l2-strategy-and-design.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
