Uploaded December 2025 | Updated September 2026, 3 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/55/OWASP%20DC%202025%20Privacy%20Project.pdf
Ask ten engineers what "privacy by design" means, and you’ll get ten different answers—and most of them won’t help you ship both secure and privacy-aware software. The focus in AppSec has been on securing the design with Threat Modeling, securing the code, and addressing third-party risk management challenges. But what does privacy mean to software engineers? It’s fuzzy, vague, and *‘someone else’s problem’*.
This talk unpacks why privacy engineering is broken for builders—and how we're changing that. We'll share early insights from the new OWASP Privacy Reference Project, which aims to translate privacy into practical guidance for security teams, architects, and developers. AppSec voices are critical to getting this right—come help us turn privacy from a vague ideal into a usable engineering discipline.
Kim Wuyts
PwC
Privacy Engineer
Dr. Kim Wuyts is a leading privacy engineer with over 15 years of experience in security and privacy. Before joining PwC Belgium as Manager Cyber & Privacy, Kim was a senior researcher at KU Leuven where she led the development and extension of LINDDUN, a popular privacy threat modeling framework. Her mission is to raise privacy awareness and get organizations to embrace privacy engineering best practices. She is a guest lecturer, experienced speaker, and invited keynote at international privacy and security conferences such as OWASP Global AppSec, BruCON, RSA, Troopers, CPDP, and IAPP DPC. In the last few years, Kim has been delivering privacy awareness and privacy threat modeling training at many events, including academic guest lectures and corporate training. Kim is also a co-author of the Threat Modeling Manifesto+Capabilities, industry co-chair of the International Workshop on Privacy Engineering (IWPE), and a member of ENISA’s working group on Data Protection Engineering.
Matthew Coles
Matthew Coles is a Product Security Architect and Technologist with 20+ years experience working with business leaders and developers to secure hardware and software systems and processes. He is a technical contributor to community standard initiatives such as OpenSSF and OWASP, a mentor and educator, and is a maintainer of the PyTM project for threat modeling as code. Matt is a co-author of a book on Threat Modeling, a white paper on Threat Modeling through SAFECode, and the Threat Modeling Manifesto and Capabilities.
Managed by the OWASP® Foundation
owasp.org
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/55/OWASP%20DC%202025%20Privacy%20Project.pdf
Ask ten engineers what "privacy by design" means, and you’ll get ten different answers—and most of them won’t help you ship both secure and privacy-aware software. The focus in AppSec has been on securing the design with Threat Modeling, securing the code, and addressing third-party risk management challenges. But what does privacy mean to software engineers? It’s fuzzy, vague, and *‘someone else’s problem’*.
This talk unpacks why privacy engineering is broken for builders—and how we're changing that. We'll share early insights from the new OWASP Privacy Reference Project, which aims to translate privacy into practical guidance for security teams, architects, and developers. AppSec voices are critical to getting this right—come help us turn privacy from a vague ideal into a usable engineering discipline.
Kim Wuyts
PwC
Privacy Engineer
Dr. Kim Wuyts is a leading privacy engineer with over 15 years of experience in security and privacy. Before joining PwC Belgium as Manager Cyber & Privacy, Kim was a senior researcher at KU Leuven where she led the development and extension of LINDDUN, a popular privacy threat modeling framework. Her mission is to raise privacy awareness and get organizations to embrace privacy engineering best practices. She is a guest lecturer, experienced speaker, and invited keynote at international privacy and security conferences such as OWASP Global AppSec, BruCON, RSA, Troopers, CPDP, and IAPP DPC. In the last few years, Kim has been delivering privacy awareness and privacy threat modeling training at many events, including academic guest lectures and corporate training. Kim is also a co-author of the Threat Modeling Manifesto+Capabilities, industry co-chair of the International Workshop on Privacy Engineering (IWPE), and a member of ENISA’s working group on Data Protection Engineering.
Matthew Coles
Matthew Coles is a Product Security Architect and Technologist with 20+ years experience working with business leaders and developers to secure hardware and software systems and processes. He is a technical contributor to community standard initiatives such as OpenSSF and OWASP, a mentor and educator, and is a maintainer of the PyTM project for threat modeling as code. Matt is a co-author of a book on Threat Modeling, a white paper on Threat Modeling through SAFECode, and the Threat Modeling Manifesto and Capabilities.
Managed by the OWASP® Foundation
owasp.org










