Privacy by Design & Default
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic is essential as it specifically addresses Article 25 GDPR requirements for implementing data protection principles through design and default settings, covering both technical and organizational measures that must be embedded into processing systems from inception.
Overview
17 sources · Jul 15, 2026Legal Framework
Article 25 GDPR imposes two distinct but interrelated obligations on controllers: data protection by design and data protection by default. These principles, though not explicitly codified in the 1995 Data Protection Directive, were foreshadowed in its Recital 46 and are now binding legal requirements.
Under Article 25(1), controllers must implement appropriate technical and organizational measures — both at the time of determining the means of processing and at the time of the processing itself — designed to give effect to the data protection principles embedded in Article 5. Article 25(2) specifically requires that default settings ensure only personal data necessary for each specific purpose is processed. This encompasses the volume of data collected, the extent of processing, the storage period, and accessibility. The measures must account for the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects.
Technical measures may include disabling functionalities within standard software configurations, while organizational measures encompass access rights allocation among personnel. Recital 78 reinforces that controllers should adopt internal policies and implement measures such as data minimization, pseudonymization, and transparency-by-design to demonstrate compliance. The AI Act Recital 69 extends these principles to the entire lifecycle of AI systems, explicitly referencing data minimization and data protection by design and default as applicable when personal data are processed, including through anonymization, encryption, and federated learning approaches.
Key Developments
The CJEU's ruling in Digital Rights Ireland established that data retention obligations themselves constitute interference with fundamental rights, underscoring that design choices must be proportionate and necessary from inception. In Worten, the CJEU confirmed that the obligation to adopt technical and organizational measures rests squarely on controllers — not Member States — and must reflect the state of the art and cost of implementation relative to the risks presented. The court emphasized that access must be restricted to duly authorized persons.
The Schrems II judgment highlighted how technological scale and globalization amplify the stakes of design decisions, particularly around data transfers. In the Dutch WAMCA proceedings against Google, the court is examining whether excessive data collection, cross-product data combination, continuous behavioral tracking, and real-time bidding data sharing violate privacy obligations — a direct challenge to design and default configuration choices.
Enforcement actions confirm regulators actively scrutinize Article 25 compliance. The Romanian DPA fined Continental Automotive Products €15,000 and Premier Restaurants Romania €8,000, both involving failures in default configuration and organizational safeguards. The EDPB's Guidelines 4/2019 on Article 25 provide the authoritative interpretive framework, while Guidelines 1/2020 on connected vehicles demonstrate sector-specific application of these principles.
Practical Guidance
Embed data protection into system architecture from the earliest design phase. Article 25(1) requires measures at the time of determining processing means — not as a retrofit. Involve the DPO at project inception, as early involvement facilitates compliance and ensures data protection principles shape design decisions.
Configure default settings to enforce data minimization. Article 25(2) mandates that defaults limit processing to what is necessary for the specific purpose. Disable non-essential software functionalities by default, restrict data collection fields to the minimum required, and set default retention periods to the shortest necessary timeframe.
Document the state-of-the-art assessment. Controllers must demonstrate they considered available technologies and their costs. Record which measures were evaluated, why specific ones were selected or rejected, and how they correspond to identified risks — this documentation is essential for accountability under Article 5(2).
Implement layered access controls as an organizational measure. Following Worten, ensure that personnel access rights are purpose-limited and role-based, with technical enforcement preventing unauthorized data access beyond what each function requires.
Leverage approved codes of conduct and certifications. Article 25(3) provides that adherence to approved codes of conduct or certification mechanisms serves as an element demonstrating compliance — use these frameworks as benchmarks for design decisions where sector-specific instruments exist.