Why Privacy Education Starts With the Basics
Most people who build for the open web were never taught what privacy actually is. Not in school, not on the job, and not in any formal accreditation process. Designers, developers, and project managers typically encounter privacy only through compliance checklists, legal warnings, or after-the-fact fixes for problems someone else created. That gap in foundational knowledge is what Understanding Privacy aims to fill — both for people already working in the field and for students entering it through universities, vocational programs, or code academies.
The book is structured around the idea that a healthy approach to privacy should be built in from the start, not retrofitted at the end. The hope is that educators will adopt it as the basis for a proper curriculum, so that future developers learn privacy as a core professional skill rather than as an afterthought.
An Industry With No Common Standard
One of the challenges in teaching privacy is that web development is not, in the legal sense, a profession. Professions are defined by industry bodies, common entry paths, shared educational requirements, and continuing professional development — all backed by external standards that work can be measured against. Web development has none of that. Anyone can enter the field at any time, with any level of training or none at all, without any external certification or approval.
A computer science graduate and a former airline pilot who learned to code for fun can end up on the same team doing the same work. That occupational diversity has helped the open web grow, and diverse teams often produce better results precisely because of their different perspectives. But it also means that the knowledge of privacy that people bring to their work is inconsistent — when it exists at all. Without a common educational pathway, the social, legal, and cultural differences around privacy that are discussed in Part One of the book continue to show up in the products and services people build.
The result is that users pay the price for that inconsistency. And waiting for educators, employers, or institutions to fill the gap is not a viable option. Self-education on privacy has never been more critical, even if a single book can only do so much.
The Political Push for Liability
The urgency around privacy education has grown sharper in recent years due to shifts in tech policy. Regulators in multiple jurisdictions are increasingly proposing personal liability regimes for digital services, which would hold the people who build the web legally — and sometimes criminally — responsible for misuse or unintended consequences of their work.
Some of these proposals come from genuine pressure to address the state of the open web. Others are driven by a desire to appear tough on big tech, with politicians often conflating individual companies with the entire internet. Still others are naked power plays or attempts to delegate censorship and content control to the tech sector. Whatever the motivation, these proposals are not going away — they are getting louder.
Many of these draft regulations borrow models from health and safety regimes. But they fail to recognize that human discourse cannot be regulated the way you would regulate fire-retardant cladding on a building. Trying to force human interaction into a “risk assessment” framework creates an unworkable legal standard: the person who misuses a service is not held liable, but the person who built the service is.
Who Really Bears the Risk
The proposed liability regimes were largely drafted with a handful of high-profile American tech executives in mind. In fact, some target three specific individuals at two companies, as if their imprisonment would solve the internet’s problems. Whether those individuals are guilty or complacent is beside the point.
Once such laws are on the books, wealthy executives can afford legal defenses that let them dodge the charges. But because politicians insist that “something has to be done” and “someone needs to pay,” enforcement will inevitably fall on easier targets — smaller companies, independent developers, and people without the resources to fight back.
Policymakers are turning their attention to the people who make the web, not to support their careers but to find someone to blame. The idea of arresting and prosecuting developers has been raised openly by politicians seeking a quick political win in front of the cameras. Those policymakers are in ascendancy. And when they need an easy target, there you are — no formal qualifications, no foundational training, no professional body to defend you — building things that millions of people use.
Privacy as a Form of Protection
Understanding Privacy was written to contribute to a better open web, and the tone is deliberately constructive. But the book’s lessons don’t exist in a vacuum. They operate in a political climate where the people who make the web have become targets.
The practical takeaway is twofold. By reading the book, you learn how to protect users in everything you build, with or without privacy legislation in place. But in the current political climate, those same lessons can help you protect yourself too. In the absence of any formal curriculum, workplace training, professional body, or legal standard, the book provides a way to create an accountable and documented framework around privacy in your work. That framework can’t protect you on its own, but it might help when the day comes that you and your team become the target of an ambitious politician’s campaign — instead of the billionaires in Silicon Valley.
The “oxygen mask” rule applies here: secure your own mask before helping others. As you use the book to build a better web for your users, it’s worth thinking about how its lessons can protect you as well, especially given policymakers’ focus on punishing tech celebrities at any cost — a focus that views independent developers as expendable collateral damage. And as the book’s Part Four discusses, consider the developers who will come after you, and what kind of world they could build with a proper education in foundational privacy. Or, at the very least, with more than just one book.
Format and Availability
Understanding Privacy is offered as a quality hardcover with stitched binding and a ribbon page marker, plus a DRM-free eBook available in PDF, ePUB, and Amazon Kindle formats. The print edition carries ISBN 978-3-945749-64-7.
- Print Hardcover + eBook: $44.00 — includes free worldwide shipping from Germany and a 100-day money-back guarantee.
- eBook only: $19.00 — free for Smashing Members, with direct downloads for PDF, ePUB, and Kindle.

For eBook-only purchases, download links are provided for each format:
All copies are covered by the publisher’s money-back guarantee, ensuring a risk-free purchase regardless of format.



