Privacy by Design & Default
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic is essential as it specifically addresses Article 25 GDPR requirements for implementing data protection principles through design and default settings, covering both technical and organizational measures that must be embedded into processing systems from inception.
Overview
17 sources · Jul 15, 2026Legal Framework
Article 25 GDPR imposes two distinct but interrelated obligations on controllers: data protection by design and data protection by default. These principles, though not explicitly codified in the 1995 Data Protection Directive, were foreshadowed in its Recital 46 and are now binding legal requirements.
Under Article 25(1), controllers must implement appropriate technical and organizational measures — both at the time of determining the means of processing and at the time of the processing itself — designed to give effect to the data protection principles embedded in Article 5. Article 25(2) specifically requires that default settings ensure only personal data necessary for each specific purpose is processed. This encompasses the volume of data collected, the extent of processing, the storage period, and accessibility. The measures must account for the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects.
Technical measures may include disabling functionalities within standard software configurations, while organizational measures encompass access rights allocation among personnel. Recital 78 reinforces that controllers should adopt internal policies and implement measures such as data minimization, pseudonymization, and transparency-by-design to demonstrate compliance. The AI Act Recital 69 extends these principles to the entire lifecycle of AI systems, explicitly referencing data minimization and data protection by design and default as applicable when personal data are processed, including through anonymization, encryption, and federated learning approaches.
Key Developments
The CJEU's ruling in Digital Rights Ireland established that data retention obligations themselves constitute interference with fundamental rights, underscoring that design choices must be proportionate and necessary from inception. In Worten, the CJEU confirmed that the obligation to adopt technical and organizational measures rests squarely on controllers — not Member States — and must reflect the state of the art and cost of implementation relative to the risks presented. The court emphasized that access must be restricted to duly authorized persons.
The Schrems II judgment highlighted how technological scale and globalization amplify the stakes of design decisions, particularly around data transfers. In the Dutch WAMCA proceedings against Google, the court is examining whether excessive data collection, cross-product data combination, continuous behavioral tracking, and real-time bidding data sharing violate privacy obligations — a direct challenge to design and default configuration choices.
Enforcement actions confirm regulators actively scrutinize Article 25 compliance. The Romanian DPA fined Continental Automotive Products €15,000 and Premier Restaurants Romania €8,000, both involving failures in default configuration and organizational safeguards. The EDPB's Guidelines 4/2019 on Article 25 provide the authoritative interpretive framework, while Guidelines 1/2020 on connected vehicles demonstrate sector-specific application of these principles.
Practical Guidance
Embed data protection into system architecture from the earliest design phase. Article 25(1) requires measures at the time of determining processing means — not as a retrofit. Involve the DPO at project inception, as early involvement facilitates compliance and ensures data protection principles shape design decisions.
Configure default settings to enforce data minimization. Article 25(2) mandates that defaults limit processing to what is necessary for the specific purpose. Disable non-essential software functionalities by default, restrict data collection fields to the minimum required, and set default retention periods to the shortest necessary timeframe.
Document the state-of-the-art assessment. Controllers must demonstrate they considered available technologies and their costs. Record which measures were evaluated, why specific ones were selected or rejected, and how they correspond to identified risks — this documentation is essential for accountability under Article 5(2).
Implement layered access controls as an organizational measure. Following Worten, ensure that personnel access rights are purpose-limited and role-based, with technical enforcement preventing unauthorized data access beyond what each function requires.
Leverage approved codes of conduct and certifications. Article 25(3) provides that adherence to approved codes of conduct or certification mechanisms serves as an element demonstrating compliance — use these frameworks as benchmarks for design decisions where sector-specific instruments exist.
why this is here
the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation
This is the entire Article 25 provision, directly establishing the data protection by design and by default obligations, and it is the definitive legal basis for this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
Article 25 does not require the implementation of any specific technical and organizational measures, rather that the chosen measures and safeguards should be specific to the implementation of data protection princip les in to the particular processing in question.
The entire document is a guideline on Article 25 GDPR, directly addressing data protection by design and default.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
incorporate the 'protection of personal data' dimension from the product design phase
The document explicitly emphasizes incorporating data protection at the design phase, which is the essence of data protection by design.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
Article 25 (1) GDPR specifies that controllers shall implement appropriate technical and organisational measures, which are designed to implement data-protection principles.
The document has a dedicated section on data protection by design and default, and uses Article 25 as a key legal basis.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the controller should consider physical and technical means, for example blocking out or pixelating not relevant areas.
Advises on design choices to minimize data collection, a component of data protection by design, but not framed as Article 25 compliance.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
implement appropriate technical and organisational measures which, having regard to the state of the art and the cost of their implementation, are to ensure a level of security appropriate to the risks represented
While the document predates Article 25 GDPR, its emphasis on state-of-the-art technical measures aligns conceptually with design-by-default principles, but it does not directly address design or default settings.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
PETs can help you demonstrate a ‘data protection by design and by default’ approach to your processing.
The document directly links PETs to the Article 25 concept of data protection by design and default, making it a primary resource for practical application of this principle.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the privacy-by-design requirements and security requirements (which also incorporate the RBA) remain applicable when transferring data
The document briefly references Article 25 as an example of risk-based obligations, but the main focus is on Article 24 and transfers.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
must either remediate the noncompliance with supplementary measures
The suggestion of supplementary measures touches on design considerations but is not explicitly about Article 25.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
children between the ages of 13 and 17 who were allowed to operate business or creator Instagram accounts
The issue of children being allowed business accounts suggests a design/default problem, but the document does not explicitly discuss Article 25.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 55 Guidance · all 437 Enforcement · all 36 Literature