Privacy-aware product design
Product surfaces are expected to collect, store, and expose only the data needed for the workflow.
Sensitive-data movement should stay explicit in service contracts, logs, and operator documentation so review is practical later.