Skip to content
GDPR Art. 25 EN
LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this article. Contains: the article text, related recitals, cases citing it, enforcement stats and top fines, guidance, and related topics. Everything links back to its source on overview.legal — legal information, not advice.

Data protection by design and by default

In force — consolidated2016-05-04 · CELEX 02016R0679-20160504 · ELI ↗
Version history 2
  • 2016-05-04in force CELEX 02016R0679-20160504
  • 2016-04-27 CELEX 32016R0679
  1. 1.

    Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.

  2. 2.

    The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.

  3. 3.

    An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.

Enforcement

Cited in 245 fines totalling €944.1M

Top authority: 🇪🇺Italian Data Protection Authority (Garante) (69) · median fine €50,000 · see all enforcement for Art. 25 →

Connections by provision

25(1) 26 Case Law 147 Enforcement 51 Guidance 3 Literature .md
25(2) 33 Case Law 22 Enforcement 34 Guidance 2 Literature .md
25(3) 8 Case Law 6 Guidance .md

Related across sources

C-741/21 GP v juris GmbH In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject… CJEU ·Third Chamber Apr 11, 2024 Liability Personal Data Integrity and Confidentiality Principle
15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 Privacy by Design & Default Privacy by Design DPIA
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
473833 The DPA imposed an €8 million administrative fine on Apple (the controller) in 2022 (CNIL - SAN-2022-025) The DPA found that Apple used identifiers stored on users’ devices to enable personalized advertising in the App Store without first obtaining valid user consent, as required by… CE - 473833 ·Supreme Administrative Court Oct 10, 2025 Material scope (GDPR) Personal Data Consent