A connection to the application.
Privacy API integration was intended to connect HR and proprietary business systems with a shared place for privacy decisions.
A cross-border privacy concept
Canada / EuropeA policy layer for sensitive information crossing borders. Connecting the needs of your application with the rules of its destination.
Sensitive information moves through applications, teams and infrastructure. When it crosses jurisdictions, the context matters: who is requesting it, where it is going and how it will be handled.
PrivacyOne explored bringing these decisions into a shared policy layer. The aim: help applications apply privacy controls consistently, with a clearer record of the decisions behind each transfer.
02 / Inside the architecture
Follow a hypothetical request through the proposed PrivacyOne layer. Select a stage to see the reasoning behind it.
An application supplies the context of a proposed transfer: the requester, the data category and the intended destination.
Illustrative architecture, not a live service. No data is transmitted or assessed by this walkthrough. A policy decision would depend on configured rules and appropriate review.
The original concept connected integration, access control and auditing around a shared question: should this information move?
Privacy API integration was intended to connect HR and proprietary business systems with a shared place for privacy decisions.
A Zero Trust direction: evaluate access in context, limit permissions and avoid treating a network location as sufficient trust.
Auditing should make it easier to understand what was requested, which policy informed a decision and where information was intended to go.
Bring risk controls and privacy review into repeatable workflows, supporting the people responsible for decisions and exceptions.
04 / Jurisdiction matters
PrivacyOne’s original focus was cross-border handling of personal information involving Canadian and European environments. The concept puts the transfer context ahead of the destination alone.
Origin, purpose and handling requirements travel with the request.
Destination, permitted use and safeguards inform the decision.
Geographic context is only part of a privacy assessment. This concept does not provide legal advice, certify compliance or replace the review of applicable obligations.
05 / The original team
The people behind the original PrivacyOne project, with their roles from that period.
Policy Lead
Policy Lead
Technical Lead
Technical Lead
The next chapter
Development is currently paused pending funding. This site documents the PrivacyOne concept and technical direction while opportunities for its next stage are explored.
Opens your email app. Original project contact; availability is unconfirmed.