Notice
A clear explanation of an important data practice, purpose, recipient, or consequence.
Engineering question: Does the explanation appear where the user can understand it before or when the relevant decision matters?
Strong pattern: A scheduling form explains that selected contact details will be shared with the approved scheduling partner for appointment coordination.
Weak pattern: A broad statement says data may be used to improve services without identifying the actual sharing or purpose.
Consent
A meaningful user choice for a defined data practice when choice is appropriate to the context.
Engineering question: Is the choice specific, understandable, voluntary, and tied to the real behavior of the system?
Strong pattern: Optional notifications remain off until the user chooses a channel.
Weak pattern: Optional tracking is bundled into acceptance of an unrelated required service.
Transparency
The broader ability for people to understand how important data practices work.
Engineering question: Could a reasonable user understand the system's major collection, use, sharing, and retention practices?
Strong pattern: Product explanations are concise, layered, and consistent with the actual data flow.
Weak pattern: The interface is simple, but the backend performs materially different uses that are not explained.
User expectation
What a reasonable user would anticipate based on context, service purpose, prior explanation, and normal product behavior.
Engineering question: Would the actual data use feel consistent with the user's reason for providing the information?
Strong pattern: A support request is used to provide and improve that support service.
Weak pattern: Support-case details are reused for unrelated individual profiling.
Default
The system state that applies when the user takes no action.
Engineering question: Does the default protect privacy without blocking the legitimate core service?
Strong pattern: Optional promotional notifications are off by default; required service notifications remain appropriately enabled.
Weak pattern: All optional uses are preselected because most users will not change them.
Choice architecture
How options, explanations, timing, wording, and interface structure shape a user's decision.
Engineering question: Are options presented fairly, or is the interface designed to push users toward more data collection?
Strong pattern: Accept and decline choices are comparably visible and understandable.
Weak pattern: The accept button is prominent while the decline path is hidden behind several screens.
Withdrawal / change
The ability to revisit an optional choice when the product or user preference changes.
Engineering question: Can the user change a choice without losing unrelated core functionality?
Strong pattern: Notification preferences can be updated from the same settings area used to enable them.
Weak pattern: Opting out requires contacting support while opting in takes one click.
Contextual integrity
The idea that privacy expectations depend on who is sharing what information, for what purpose, with whom, and under what social or service context.
Engineering question: Does the data flow fit the original context, or does it introduce a new audience or purpose?
Strong pattern: A scheduling partner receives only the fields needed to complete the scheduling service.
Weak pattern: The same partner receives unrelated support history because the data is technically available.