Skip to content
Topic Contested in court

Privacy by Default

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Ensuring highest privacy settings apply by default

131 linked items 6 Laws17 Case Law49 Guidance30 Enforcement5 News

Overview

24 sources · Jul 23, 2026

Legal Framework

The governing provision is Article 25 GDPR, which consolidates two related but distinct obligations: data protection by design (paragraph 1) and data protection by default (paragraph 2). Article 25(2) imposes a specific, operational duty on controllers to configure their systems so that the most privacy-protective settings apply automatically — without requiring the data subject to take affirmative steps.

"The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed."
— GDPR Art. 25(2)

The scope of this obligation is deliberately broad. It extends across four dimensions of the processing lifecycle:

"That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility."
— GDPR Art. 25(2)

Recital 78 reinforces this framework by situating the default-setting obligation within the broader accountability principle, listing concrete measures such as data minimisation, pseudonymisation, and transparency as means of demonstrating compliance. Article 47(d) also references data protection by design and by default as a required element of binding corporate rules, meaning the obligation extends into intra-group transfer governance.

Key Developments

The Court of Justice of the European Union has begun to articulate the practical boundaries of Article 25 in preliminary rulings. In X v Russmedia Digital SRL (2 December 2025), the Grand Chamber examined the responsibility of an online marketplace operator for personal data published in user advertisements and linked that analysis directly to the default-setting obligation:

This framing confirms that the accessibility dimension of Article 25(2) is not merely aspirational: controllers must configure platforms so that personal data is not publicly exposed by default. The same judgment references Article 25(1) and (2) in full at paragraph 22, anchoring the default-setting analysis in the text of both paragraphs rather than treating them as separable obligations.

At the enforcement level, the Italian Garante fined the Calabrian Regional Agency for Agricultural Development €50,000 for a remote work policy that failed to embed privacy-protective defaults, and the EDPB's Guidelines 4/2019 on Article 25 remain the principal regulatory interpretive instrument, emphasising that default settings must be configured at the point of system design, not retrofitted.

Status of the Debate

This topic is contested in court. The CJEU's Russmedia ruling represents an early judicial articulation of how Article 25(2) applies to platform operators, but the boundaries — particularly what constitutes "necessary" data for a "specific purpose" when multiple processing objectives coexist within a single service — remain actively litigated. The WAMCA proceedings against Google in the Netherlands, which challenge excessive data collection and cross-service bundling, will test whether Article 25(2) imposes categorical limits on data combination by default. What would resolve the open question is a CJEU ruling addressing whether the default-setting obligation operates as an independent prohibition on over-collection or merely as a procedural safeguard to be assessed alongside Article 5(1)(c) data minimisation.

Practical Guidance

  • Map defaults to each processing purpose individually. Article 25(2) requires that necessity is assessed per specific purpose, not globally. Configure separate default settings for each identified purpose so that no purpose inherits data collected for another.
  • Restrict default accessibility. Ensure that personal data is not publicly visible by default; require affirmative user action before data becomes accessible to an indefinite number of persons, as confirmed in Russmedia ¶89.
  • Apply the four-dimensional test. Audit the amount of data collected, the extent of processing, the storage period, and accessibility — each must be set to the minimum necessary by default.
  • Document design decisions contemporaneously. Recital 78 links compliance demonstration to internal policies and measures; maintain records showing why specific default settings were chosen, including state-of-the-art and cost-of-implementation considerations.
  • Use certification as evidence. Article 25(3) permits approved certification mechanisms under Article 42 as an element demonstrating compliance — pursue certification where available for your sector to substantiate the adequacy of your default configurations.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 25 Data protection by design and by default Laws GDPR Apr 2016 Default data minimisation and restricted accessibility
why this is here
The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed.

Paragraph 2 is the explicit legal requirement for privacy by default, covering data minimisation, storage, and accessibility by default.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Guidance EDPB Oct 2020 Data protection by default
why this is here
Article 25(2) respectively

The document explicitly covers data protection by default in Article 25(2), making it a primary source.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 03/2022 Deceptive design patterns in social media platform interfaces: how to recognise and avoid them Guidelines ·EDPB Guidance EDPB Feb 2023 Privacy by default requirements
why this is here
Article 25 (2) GDPR clarifies that such measures shall also be implemented for ensuring that, by default, only personal data which are necessary for each specific processing purpose are processed.

The document explicitly discusses the default requirements of Article 25, making it a primary source for this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Design-phase privacy
why this is here
protection of personal data dimension from the product design phase

The document's emphasis on design phase is related to privacy by design, and by default by implication, though not explicitly stated.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 06/2020 interplay of the Second Payment Services Directive and the GDPR Guidelines on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Guidelines ·EDPB Guidance EDPB Dec 2020 Privacy by default mention
why this is here
data protection by design and data protection by default should be embedded

Only a brief mention in a recital, not a substantive treatment.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

ICO: How can Privacy Enhancing Technologies help with data protection compliance? > How can PETs help with data protection compliance? At a glance • PETs can help you demonstrate a ‘data protection by design and by default’ approach to your processing. • PETs… News ICO Nov 2025 by default aspect of PETs
why this is here
PETs can help you demonstrate a ‘data protection by design and by default’ approach

The document explicitly includes 'by default' in its framing, but it does not elaborate on default settings or configurations, so it is only indirectly relevant to the specific privacy-by-default topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

What Happened to the Risk-Based Approach to Data Transfers? The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute… News Future of Privacy Forum Sep 2022 RBA in Art 25
why this is here
the privacy-by-design requirements and security requirements (which also incorporate the RBA)

The document references Article 25 as an example of risk-based provisions but does not elaborate on privacy by default.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 49 Guidance · all 30 Enforcement · all 24 Literature