Skip to content
Sahn-ı BA; The Courtyard of Basmalah
TREN
SAHN.BA

BA Internet Principle · 05

Privacy is not a setting.

Privacy cannot be a feature that people must find and switch on inside long menus. A system should begin with minimum data, limited access, safe defaults and clear human consent.

Protect from the start · Minimum data · Safe defaults · Clear consent

Core principle

Protection begins while the system is being designed—not after data has been collected.

Privacy is built through the amount of data, retention periods, access rights, model use, interface defaults and the path of deletion. Responsibility cannot be placed on the person using the system alone.

Do not ask people to configure their own protection; configure the system to protect people.

A useful distinction

A setting pushes responsibility onto the user; architecture places responsibility on the system.

01

Added later

Privacy as a setting

  • Tracking on by default
  • Confusing permission screens
  • Indefinite retention
  • Hidden third-party transfer
02

Built from the start

Privacy architecture

  • Protection by default
  • Minimum data
  • Limited retention and access
  • Clear transfer and deletion

Layers of protection

Privacy is not one button; it is six limits working together.

01

Data minimisation

Data that is not needed is not collected.

02

Safe defaults

Tracking, sharing and public visibility begin turned off.

03

Purpose limitation

Data taken for one purpose is not quietly reused for another.

04

Access records

Human, service and model access remains traceable.

05

Child and family protection

Age, parental responsibility and family privacy each receive distinct protection.

06

Deletion and exit

People can download and delete their data and end the relationship.

Related BA Internet principles

Privacy is a shared consequence of decisions about people, data, models and interfaces.