Create a secure service that protects users' privacy

Users trust government services with sensitive information. Security and privacy failures erode that trust instantly — and can cause harm far beyond a broken button.

Design security and privacy into the architecture, not as afterthoughts. Collect only the data you need, store it appropriately, and make users confident their information is handled responsibly.

Security is designed in: threat modelling, access controls, encryption, and secure development practices from the start. Privacy means collecting only what you need, explaining why, and handling data responsibly throughout its lifecycle.

Teams should involve security and data specialists early, especially when identity, payments, or personal records are involved — not briefing them days before launch.

How teams usually demonstrate this

  • Security and privacy considerations documented from early phases
  • Data minimisation — only collecting necessary fields
  • Appropriate authentication and authorisation for the risk level
  • Incident response planning before go-live

Phases where this often matters

See also delivery phase guides and how frameworks fit together.

Related standard points

Point 9 of the Service Standard is published by the Government Digital Service on GOV.UK. Content is available under the Open Government Licence v3.0. UCD Services explains the standard in its own words and is not affiliated with GOV.UK or the Government Digital Service.