Privacy by Design: What Are Engineers Supposed to Do With That? @OWASPGLOBAL
Privacy by Design: What Are Engineers Supposed to Do With That?  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 3 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/55/OWASP%20DC%202025%20Privacy%20Project.pdf

Ask ten engineers what "privacy by design" means, and you’ll get ten different answers—and most of them won’t help you ship both secure and privacy-aware software. The focus in AppSec has been on securing the design with Threat Modeling, securing the code, and addressing third-party risk management challenges. But what does privacy mean to software engineers? It’s fuzzy, vague, and *‘someone else’s problem’*.

This talk unpacks why privacy engineering is broken for builders—and how we're changing that. We'll share early insights from the new OWASP Privacy Reference Project, which aims to translate privacy into practical guidance for security teams, architects, and developers. AppSec voices are critical to getting this right—come help us turn privacy from a vague ideal into a usable engineering discipline.

Kim Wuyts
PwC
Privacy Engineer

Dr. Kim Wuyts is a leading privacy engineer with over 15 years of experience in security and privacy. Before joining PwC Belgium as Manager Cyber & Privacy, Kim was a senior researcher at KU Leuven where she led the development and extension of LINDDUN, a popular privacy threat modeling framework. Her mission is to raise privacy awareness and get organizations to embrace privacy engineering best practices. She is a guest lecturer, experienced speaker, and invited keynote at international privacy and security conferences such as OWASP Global AppSec, BruCON, RSA, Troopers, CPDP, and IAPP DPC. In the last few years, Kim has been delivering privacy awareness and privacy threat modeling training at many events, including academic guest lectures and corporate training. Kim is also a co-author of the Threat Modeling Manifesto+Capabilities, industry co-chair of the International Workshop on Privacy Engineering (IWPE), and a member of ENISA’s working group on Data Protection Engineering.

Matthew Coles

Matthew Coles is a Product Security Architect and Technologist with 20+ years experience working with business leaders and developers to secure hardware and software systems and processes. He is a technical contributor to community standard initiatives such as OpenSSF and OWASP, a mentor and educator, and is a maintainer of the PyTM project for threat modeling as code. Matt is a co-author of a book on Threat Modeling, a white paper on Threat Modeling through SAFECode, and the Threat Modeling Manifesto and Capabilities.

Managed by the OWASP® Foundation
owasp.org
Privacy by Design: What Are Engineers Supposed to Do With That?SBOMs in the Real World: Practical Guidance for Managing Three Common SBOM ScenariosInfluencing Without Authority: The Foundations of a Successful Security Department of YesOWASP Global Board of Directors - November 2025OWASP Serverless Top 10 - David Melamed, Aruneesh SalhotraOWASP Global Board of Directors Public Board Meeting - August 2026OWASP Application Security Verification Standard (ASVS) - Shanni Prutchi, Ryan ArmstrongKeynote by Daniel Miessler: The Future of AppSec Is Continuous ContextKeynote: Nemo Resideo: Managing Application Security Through Rapid Change - Sarah-Jane MaddenASVS Testing: You Keep Using Those WordsOWASP Finance Overview PresentationAttacking AI
OWASP Foundation |

Privacy by Design: What Are Engineers Supposed to Do With That?

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER