The functionality compromise
Every new feature is a privacy decision. How to weigh user value against data risk without grinding product delivery to a halt.
Every new feature is a privacy decision, whether the product team recognises it or not. The question for privacy programmes is how to ensure the decision is made deliberately, with the right information, and without becoming a gate that grinds product delivery to a halt. This is the functionality compromise, and getting it right is one of the highest-leverage things a privacy function can do.
The failure mode at one end is a privacy function that has no visibility of product decisions until launch. Features ship with data flows that no one has assessed, retention that no one has set, and consent flows that were bolted on at the last minute. The privacy debt accumulates until an incident or an audit forces a costly retrofit.
The failure mode at the other end is a privacy function that has become a gate. Every feature requires a full DPIA, every DPIA takes weeks, and the engineering team either routes around the process or slows to accommodate it. Privacy becomes the thing that stops the roadmap, and the trust required for genuine collaboration erodes.
The working middle is a tiered approach. A short privacy screening questionnaire embedded in the design review for every feature, taking ten minutes and producing a clear tier: no privacy review needed, lightweight review needed, or full DPIA required. The tiering criteria should be published and stable, so that engineering teams can predict which tier a feature will land in.
The lightweight review is where most features should end up. A thirty-minute conversation between a privacy specialist and the feature owner, resulting in a one-page record of the data flows, the lawful basis, the retention, and any specific controls. This is enough for the majority of features, and it produces documentation that is genuinely useful if questions arise later.
The full DPIA is reserved for features that meet the criteria — new technology, large-scale profiling, systematic monitoring, special category data — and should be scoped to answer specific risk questions rather than to complete a template. A DPIA that runs to twenty pages and reaches no clear conclusion is worse than a five-page one that identifies three specific risks and their mitigations.
The compromise, when it works, does not slow product delivery. It embeds privacy into the design conversation early, catches the issues that would otherwise emerge at launch, and produces a body of documentation that supports both regulatory engagement and future decision-making. Privacy by design is a real thing, and it looks like this.






