Privacy by design and default
Article 25 (Data Protection by design and default) and 35 (Data Protection Impact Assessment) of the GDPR, this is general in approach, and itterative as with regard to the guidence form the UK ICO and any codes of conduct.
The idea here is to present an approach to capturing privacy (EU, UK) requirements, and designing them in to a solution, using a standard approach. This is a living document, taking an holistic approach, that takes in to account people, processes, and technology; as well as governance, risk management and compliance.
Phase one: [Capture the business case]->[Data Protection Impact Assessment]->[Ensure funding for state of the art, appropriate, proportionate privacy enhancing technologies, processes, practices, and people are available and suitable]
Phase two: [Funded business case / project]->[Capture the privacy requirements]->[Create privacy stories]->[Implement controls]-[data lifecycle management]
Phase three: [Lifecycle management]:[Birth]->[Life]->[Death] (Governance, risk and compliance)