A software development team is building a new e-commerce platform using an Agile methodology. To properly implement the 'Privacy Embedded into Design' principle, when should the privacy engineer introduce privacy requirements and controls?
-
A
As a final quality assurance check just before the production launch.
-
B
After the first major data breach to address known vulnerabilities.
-
C
During the initial sprint planning and user story creation phases.
-
D
During the deployment phase by configuring server-side security rules.