Laws · GDPR ·art-25-par-2 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
How it connects
Cited by
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Guidelines 3/2019 on processing of personal data through video devices
- ParkkiPate Oy: Insufficient fulfilment of data subjects rights
- Motor insurance center: Non-compliance with general data processing principles
All 39
- DISCORD INC.: Non-compliance with general data processing principles
- Zagreb Holding d.o.o.: Insufficient fulfilment of information obligations
- Verkkokauppa.com: Non-compliance with general data processing principles
- Company: Non-compliance with general data processing principles
- hier
- Study on the secondary use of personal data in the context of scientific research
- Guidelines 02/2025 on processing of personal data through blockchain technologies
- EDPB Annual Report 2024
- Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation
- Data Protection Commissioner v Facebook Ireland and Maximillian Schrems
- Maximillian Schrems v Data Protection Commissioner
- Bank: Non-compliance with general data processing principles
- Isabel SA: Insufficient fulfilment of data subjects rights
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- Garante per la protezione dei dati personali (Italy) - 487/2026
- Guidelines on processing of personal data through blockchain technologies
- Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)
- Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria
- Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms
- EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- EDPB Annual Report 2022
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- X v Russmedia Digital SRL and Inform Media Press SRL
- Maximilian Schrems v Meta Platforms Ireland Limited
- WM and Sovim SA v Luxembourg Business Registers
- SIA 'SS' v Valsts ieņēmumu dienests
- Tele2 (Netherlands) BV and Others v Autoriteit Consument en Markt (ACM)
- General Data Protection Regulation (GDPR) – Revolution Coming to European Data Protection Laws in 2018. What’s New for Ordinary Citizens?
- DSB (Austria) - 2025-0.950.759
- Finnish DPA: requesting address, ID number and strong authentication for access request
- US Zagreb - Us I-4772/2023-10
- Character Technologies Inc.: Non-compliance with general data processing principles
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight