A cross-border privacy concept

Canada / Europe

Data moves. Privacy should move with it.

A policy layer for sensitive information crossing borders. Connecting the needs of your application with the rules of its destination.

A policy boundary between two data environments Routes from a source environment pass through the PrivacyOne policy layer before reaching a destination. An alternative route stops at the boundary. 01 / SOURCE 02 / DESTINATION POLICY BOUNDARY CONTROLLED MOVEMENT / CONCEPT VIEW
FIG. 01 — THE POLICY BOUNDARY ILLUSTRATIVE
Privacy infrastructure, thoughtfully considered. Application → Policy → Destination
01 The approach

A border is more than
a line on a map.

Sensitive information moves through applications, teams and infrastructure. When it crosses jurisdictions, the context matters: who is requesting it, where it is going and how it will be handled.

PrivacyOne explored bringing these decisions into a shared policy layer. The aim: help applications apply privacy controls consistently, with a clearer record of the decisions behind each transfer.

02 / Inside the architecture

One request.
A considered path.

Follow a hypothetical request through the proposed PrivacyOne layer. Select a stage to see the reasoning behind it.

Concept walkthrough / CA → EU
Stage 01 / Request context

Start with the application.

An application supplies the context of a proposed transfer: the requester, the data category and the intended destination.

sourceCanadian environment
destinationEuropean environment
data categoryPersonal information

Illustrative architecture, not a live service. No data is transmitted or assessed by this walkthrough. A policy decision would depend on configured rules and appropriate review.

03 Design principles

Privacy belongs
in the workflow.

The original concept connected integration, access control and auditing around a shared question: should this information move?

Policy before transfer
IdentifyRequester & purpose
EvaluateOrigin & destination
ApplyAccess conditions
RetainDecision context
01

A connection to the application.

Privacy API integration was intended to connect HR and proprietary business systems with a shared place for privacy decisions.

02

Access with explicit boundaries.

A Zero Trust direction: evaluate access in context, limit permissions and avoid treating a network location as sufficient trust.

03

A record of the reasoning.

Auditing should make it easier to understand what was requested, which policy informed a decision and where information was intended to go.

04

More deliberate operations.

Bring risk controls and privacy review into repeatable workflows, supporting the people responsible for decisions and exceptions.

04 / Jurisdiction matters

Different environments.
A shared policy layer.

PrivacyOne’s original focus was cross-border handling of personal information involving Canadian and European environments. The concept puts the transfer context ahead of the destination alone.

Canadian environment CA

Origin, purpose and handling requirements travel with the request.

European environment EU

Destination, permitted use and safeguards inform the decision.

Geographic context is only part of a privacy assessment. This concept does not provide legal advice, certify compliance or replace the review of applicable obligations.

05 / The original team

Policy meets engineering.

The people behind the original PrivacyOne project, with their roles from that period.

Hilary
Best

Policy Lead

Dania
Omaraya

Policy Lead

Pranesh
Lakshmanasamy

Technical Lead

Majd
Hawa

Technical Lead

The next chapter

A vision worth continuing.

Development is currently paused pending funding. This site documents the PrivacyOne concept and technical direction while opportunities for its next stage are explored.

Funding & partnership enquiries ↗

Opens your email app. Original project contact; availability is unconfirmed.

Project update

A pause.
With a direction.

PrivacyOne development is currently paused while funding opportunities for the next stage are explored.

This website remains an overview of the original product vision and technical direction. It does not offer an active commercial service.

Read the project update ↗