Skip to content
Topic Contested in court

Privacy by Design & Default

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This topic is essential as it specifically addresses Article 25 GDPR requirements for implementing data protection principles through design and default settings, covering both technical and organizational measures that must be embedded into processing systems from inception.

562 linked items 6 Laws11 Case Law55 Guidance437 Enforcement17 News

Overview

17 sources · Jul 15, 2026

Legal Framework

Article 25 GDPR imposes two distinct but interrelated obligations on controllers: data protection by design and data protection by default. These principles, though not explicitly codified in the 1995 Data Protection Directive, were foreshadowed in its Recital 46 and are now binding legal requirements.

Under Article 25(1), controllers must implement appropriate technical and organizational measures — both at the time of determining the means of processing and at the time of the processing itself — designed to give effect to the data protection principles embedded in Article 5. Article 25(2) specifically requires that default settings ensure only personal data necessary for each specific purpose is processed. This encompasses the volume of data collected, the extent of processing, the storage period, and accessibility. The measures must account for the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects.

Technical measures may include disabling functionalities within standard software configurations, while organizational measures encompass access rights allocation among personnel. Recital 78 reinforces that controllers should adopt internal policies and implement measures such as data minimization, pseudonymization, and transparency-by-design to demonstrate compliance. The AI Act Recital 69 extends these principles to the entire lifecycle of AI systems, explicitly referencing data minimization and data protection by design and default as applicable when personal data are processed, including through anonymization, encryption, and federated learning approaches.

Key Developments

The CJEU's ruling in Digital Rights Ireland established that data retention obligations themselves constitute interference with fundamental rights, underscoring that design choices must be proportionate and necessary from inception. In Worten, the CJEU confirmed that the obligation to adopt technical and organizational measures rests squarely on controllers — not Member States — and must reflect the state of the art and cost of implementation relative to the risks presented. The court emphasized that access must be restricted to duly authorized persons.

The Schrems II judgment highlighted how technological scale and globalization amplify the stakes of design decisions, particularly around data transfers. In the Dutch WAMCA proceedings against Google, the court is examining whether excessive data collection, cross-product data combination, continuous behavioral tracking, and real-time bidding data sharing violate privacy obligations — a direct challenge to design and default configuration choices.

Enforcement actions confirm regulators actively scrutinize Article 25 compliance. The Romanian DPA fined Continental Automotive Products €15,000 and Premier Restaurants Romania €8,000, both involving failures in default configuration and organizational safeguards. The EDPB's Guidelines 4/2019 on Article 25 provide the authoritative interpretive framework, while Guidelines 1/2020 on connected vehicles demonstrate sector-specific application of these principles.

Practical Guidance

  • Embed data protection into system architecture from the earliest design phase. Article 25(1) requires measures at the time of determining processing means — not as a retrofit. Involve the DPO at project inception, as early involvement facilitates compliance and ensures data protection principles shape design decisions.

  • Configure default settings to enforce data minimization. Article 25(2) mandates that defaults limit processing to what is necessary for the specific purpose. Disable non-essential software functionalities by default, restrict data collection fields to the minimum required, and set default retention periods to the shortest necessary timeframe.

  • Document the state-of-the-art assessment. Controllers must demonstrate they considered available technologies and their costs. Record which measures were evaluated, why specific ones were selected or rejected, and how they correspond to identified risks — this documentation is essential for accountability under Article 5(2).

  • Implement layered access controls as an organizational measure. Following Worten, ensure that personnel access rights are purpose-limited and role-based, with technical enforcement preventing unauthorized data access beyond what each function requires.

  • Leverage approved codes of conduct and certifications. Article 25(3) provides that adherence to approved codes of conduct or certification mechanisms serves as an element demonstrating compliance — use these frameworks as benchmarks for design decisions where sector-specific instruments exist.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 25 Data protection by design and by default Laws GDPR Apr 2016 Primary source for Article 25 obligations
why this is here
the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation

This is the entire Article 25 provision, directly establishing the data protection by design and by default obligations, and it is the definitive legal basis for this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Guidance EDPB Oct 2020 Article 25 GDPR requirements
why this is here
Article 25 does not require the implementation of any specific technical and organizational measures, rather that the chosen measures and safeguards should be specific to the implementation of data protection princip les in to the particular processing in question.

The entire document is a guideline on Article 25 GDPR, directly addressing data protection by design and default.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Incorporating data protection in design
why this is here
incorporate the 'protection of personal data' dimension from the product design phase

The document explicitly emphasizes incorporating data protection at the design phase, which is the essence of data protection by design.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 03/2022 Deceptive design patterns in social media platform interfaces: how to recognise and avoid them Guidelines ·EDPB Guidance EDPB Feb 2023 Data protection by design principles
why this is here
Article 25 (1) GDPR specifies that controllers shall implement appropriate technical and organisational measures, which are designed to implement data-protection principles.

The document has a dedicated section on data protection by design and default, and uses Article 25 as a key legal basis.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Design considerations
why this is here
the controller should consider physical and technical means, for example blocking out or pixelating not relevant areas.

Advises on design choices to minimize data collection, a component of data protection by design, but not framed as Article 25 compliance.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

CJEU Worten: Controllers must implement appropriate technical and organizational security Security: Data protection law requires controllers (not Member States) to adopt technical and organizational measures which, having regard to the state of the art and cost of… Case Law CJEU May 2013 Security as design element
why this is here
implement appropriate technical and organisational measures which, having regard to the state of the art and the cost of their implementation, are to ensure a level of security appropriate to the risks represented

While the document predates Article 25 GDPR, its emphasis on state-of-the-art technical measures aligns conceptually with design-by-default principles, but it does not directly address design or default settings.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

ICO: How can Privacy Enhancing Technologies help with data protection compliance? > How can PETs help with data protection compliance? At a glance • PETs can help you demonstrate a ‘data protection by design and by default’ approach to your processing. • PETs… News ICO Nov 2025 by design and default approach
why this is here
PETs can help you demonstrate a ‘data protection by design and by default’ approach to your processing.

The document directly links PETs to the Article 25 concept of data protection by design and default, making it a primary resource for practical application of this principle.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

What Happened to the Risk-Based Approach to Data Transfers? The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute… News Future of Privacy Forum Sep 2022 RBA in Art 25/security
why this is here
the privacy-by-design requirements and security requirements (which also incorporate the RBA) remain applicable when transferring data

The document briefly references Article 25 as an example of risk-based obligations, but the main focus is on Article 24 and transfers.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures The Danish Data Protection Agency has looked into the tool Google Analytics and its settings, and the terms under which the tool is provided. On the basis of this review, the… News Datatilsynet Sep 2022 supplementary measures as design
why this is here
must either remediate the noncompliance with supplementary measures

The suggestion of supplementary measures touches on design considerations but is not explicitly about Article 25.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations > The fine is the result of an investigation that began in 2020 and focused on the company’s processing of children’s personal data. Based on press reports, the investigation… News Hunton Andrews Kurth Sep 2022 Default settings for children's accounts
why this is here
children between the ages of 13 and 17 who were allowed to operate business or creator Instagram accounts

The issue of children being allowed business accounts suggests a design/default problem, but the document does not explicitly discuss Article 25.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 55 Guidance · all 437 Enforcement · all 36 Literature