Privacy by Default
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Ensuring highest privacy settings apply by default
Overview
24 sources · Jul 23, 2026Legal Framework
The governing provision is Article 25 GDPR, which consolidates two related but distinct obligations: data protection by design (paragraph 1) and data protection by default (paragraph 2). Article 25(2) imposes a specific, operational duty on controllers to configure their systems so that the most privacy-protective settings apply automatically — without requiring the data subject to take affirmative steps.
"The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed."
— GDPR Art. 25(2)
The scope of this obligation is deliberately broad. It extends across four dimensions of the processing lifecycle:
"That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility."
— GDPR Art. 25(2)
Recital 78 reinforces this framework by situating the default-setting obligation within the broader accountability principle, listing concrete measures such as data minimisation, pseudonymisation, and transparency as means of demonstrating compliance. Article 47(d) also references data protection by design and by default as a required element of binding corporate rules, meaning the obligation extends into intra-group transfer governance.
Key Developments
The Court of Justice of the European Union has begun to articulate the practical boundaries of Article 25 in preliminary rulings. In X v Russmedia Digital SRL (2 December 2025), the Grand Chamber examined the responsibility of an online marketplace operator for personal data published in user advertisements and linked that analysis directly to the default-setting obligation:
This framing confirms that the accessibility dimension of Article 25(2) is not merely aspirational: controllers must configure platforms so that personal data is not publicly exposed by default. The same judgment references Article 25(1) and (2) in full at paragraph 22, anchoring the default-setting analysis in the text of both paragraphs rather than treating them as separable obligations.
At the enforcement level, the Italian Garante fined the Calabrian Regional Agency for Agricultural Development €50,000 for a remote work policy that failed to embed privacy-protective defaults, and the EDPB's Guidelines 4/2019 on Article 25 remain the principal regulatory interpretive instrument, emphasising that default settings must be configured at the point of system design, not retrofitted.
Status of the Debate
This topic is contested in court. The CJEU's Russmedia ruling represents an early judicial articulation of how Article 25(2) applies to platform operators, but the boundaries — particularly what constitutes "necessary" data for a "specific purpose" when multiple processing objectives coexist within a single service — remain actively litigated. The WAMCA proceedings against Google in the Netherlands, which challenge excessive data collection and cross-service bundling, will test whether Article 25(2) imposes categorical limits on data combination by default. What would resolve the open question is a CJEU ruling addressing whether the default-setting obligation operates as an independent prohibition on over-collection or merely as a procedural safeguard to be assessed alongside Article 5(1)(c) data minimisation.
Practical Guidance
- Map defaults to each processing purpose individually. Article 25(2) requires that necessity is assessed per specific purpose, not globally. Configure separate default settings for each identified purpose so that no purpose inherits data collected for another.
- Restrict default accessibility. Ensure that personal data is not publicly visible by default; require affirmative user action before data becomes accessible to an indefinite number of persons, as confirmed in Russmedia ¶89.
- Apply the four-dimensional test. Audit the amount of data collected, the extent of processing, the storage period, and accessibility — each must be set to the minimum necessary by default.
- Document design decisions contemporaneously. Recital 78 links compliance demonstration to internal policies and measures; maintain records showing why specific default settings were chosen, including state-of-the-art and cost-of-implementation considerations.
- Use certification as evidence. Article 25(3) permits approved certification mechanisms under Article 42 as an element demonstrating compliance — pursue certification where available for your sector to substantiate the adequacy of your default configurations.