Skip to content
Topic Contested in court

Privacy by Design

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Embedding data protection into system design from the outset

189 linked items 6 Laws18 Case Law78 Guidance48 Enforcement12 News

Overview

24 sources · Jul 23, 2026

Legal Framework

The primary governing provision is Article 25 GDPR, which imposes two distinct but related obligations: data protection by design (paragraph 1) and data protection by default (paragraph 2). The controller must implement appropriate technical and organisational measures at two stages — both when determining the means of processing and during the processing itself. The article requires a contextual, risk-based assessment:

"Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation"
— GDPR Art. 25(1)

Paragraph 2 adds the by default dimension: by default, only data necessary for each specific purpose may be processed. This applies to the amount collected, the extent of processing, the storage period, and accessibility. The default setting must ensure that personal data are not made accessible to an indefinite number of persons without the individual's intervention.

Recital 78 elaborates on these measures, listing minimisation, pseudonymisation, transparency, and enabling data-subject monitoring as concrete examples. Article 47(2)(d) reinforces that data protection by design and by default must be embedded in binding corporate rules for international transfers.

Key Developments

The CJEU's December 2025 judgment in X v Russmedia Digital SRL confirms that Article 25 is not merely aspirational but operational. The Court restated the provision verbatim and then applied it to an online marketplace operator, holding that:

"Article 25(1) of the GDPR requires that the controller must, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures that are designed to implement data-protection principles in an effective manner and to integrate the necessary safeguards into the processing"
— CJEU, X v Russmedia Digital, ¶89

This signals that controllers cannot defer data-protection considerations to a post-hoc compliance layer; the design phase is where the obligation bites. The Court further tied Article 25(2) to accessibility controls, emphasising that default settings must prevent unrestricted exposure of personal data.

At the enforcement level, the Italian Garante fined the Calabrian Regional Agency €50,000 for a remote-work system that failed to embed privacy safeguards by design, while the Spanish AEPD addressed failures in identity verification design in its DIGI Telecom decision. The EDPB's Guidelines 01/2021 connect Article 25 to breach preparedness, noting that by-design analysis should feed into a controller's personal data breach handbook, ensuring faster incident response.

Status of the Debate

Privacy by Design is actively litigated but doctrinally unsettled at the margins. The core obligation — that controllers must embed data-protection principles from the design stage — is firmly established in the GDPR text and confirmed by the CJEU in Russmedia. What remains contested is the threshold of appropriateness: how much technical or organisational effort is "appropriate" given state-of-the-art, cost, and risk. Courts and DPAs diverge on whether generic measures suffice or whether controllers must demonstrate specific, documented design choices for each processing operation. No court split is formally on record, but the WAMCA proceedings against Google illustrate that collective actions increasingly target design-level failures — excessive data collection, cross-service bundling, and tracking-by-default — as Article 25 breaches. What would resolve the open question is a CJEU reference explicitly addressing the proportionality calculus under Article 25(1) and the standard of proof for compliance.

Practical Guidance

  • Document design decisions at the outset. Article 25(1) requires measures at the time of determining processing means. Maintain a design-phase record showing which data-protection principles were considered, what measures were chosen, and why alternatives were rejected. This documentation is your primary defence.
  • Configure default settings restrictively. Article 25(2) demands that by default only necessary data are processed. Audit every system for default data collection scope, retention period, and access permissions — each must be set to the minimum necessary for the stated purpose.
  • Involve the DPO early in system design. Recital 78 and the Article 29 Working Party framework require that the DPO be engaged before design decisions are locked in, not after deployment.
  • Use certification as evidence. Article 25(3) expressly permits approved certification mechanisms under Article 42 to demonstrate compliance — pursue relevant certifications where available to shift the burden of proof.
  • Integrate by-design analysis into breach response. The EDPB recommends that design-phase analysis feed directly into a personal data breach handbook, ensuring that when incidents occur, the organisation can respond swiftly with pre-mapped risks and mitigation paths.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 25 Data protection by design and by default Laws GDPR Apr 2016 Design-time integration of data protection
why this is here
both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles

Paragraph 1 is the foundational obligation requiring data protection to be embedded into the design of processing systems, making it the primary source for this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 03/2022 Deceptive design patterns in social media platform interfaces: how to recognise and avoid them Guidelines ·EDPB Guidance EDPB Feb 2023 Privacy by design principles
why this is here
the requirements of data protection by design and default under Article 25 GDPR play a vital role

The document extensively elaborates on privacy by design principles and their application to interface design.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 1/2018 certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation Guidelines ·EDPB Guidance EDPB Jun 2019 Article 25 as certification criterion
why this is here
the obligation of data protection by design and by default, pursuant to Article 25;

The document mentions Article 25 as one of the compliance aspects for certification criteria, but does not elaborate on design or default principles.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 design principle mention
why this is here
how to integrate data protection by design and by default, enabling data subjects to have effective control over their data

The document references national guidance on privacy by design in a factual background note, but does not analyze or elaborate the principle itself.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 06/2020 interplay of the Second Payment Services Directive and the GDPR Guidelines on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Guidelines ·EDPB Guidance EDPB Dec 2020 Privacy by design mention
why this is here
data protection by design and data protection by default should be embedded in all data processing systems

Only a brief reference, not a detailed discussion.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Design considerations
why this is here
the controller should consider physical and technical means, for example blocking out or pixelating not relevant areas.

Implies embedding data protection into system design, but does not explicitly reference Article 25 or use the term 'privacy by design'.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

ICO: How can Privacy Enhancing Technologies help with data protection compliance? > How can PETs help with data protection compliance? At a glance • PETs can help you demonstrate a ‘data protection by design and by default’ approach to your processing. • PETs… News ICO Nov 2025 embedding PETs in design
why this is here
PETs can help you demonstrate a ‘data protection by design and by default’ approach to your processing.

The document centers on PETs as tools to implement privacy by design, directly addressing how technical measures can embed data protection from the outset.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

What Happened to the Risk-Based Approach to Data Transfers? The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute… News Future of Privacy Forum Sep 2022 RBA in Art 25
why this is here
the privacy-by-design requirements and security requirements (which also incorporate the RBA) remain applicable when transferring data

The document mentions privacy by design as an analogous risk-based obligation but does not analyze it in depth.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures The Danish Data Protection Agency has looked into the tool Google Analytics and its settings, and the terms under which the tool is provided. On the basis of this review, the… News Datatilsynet Sep 2022 supplementary measures as design
why this is here
remediate the noncompliance with supplementary measures

The suggested supplementary measures relate to design of data transfer solutions but are not framed as Article 25 compliance.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations > The fine is the result of an investigation that began in 2020 and focused on the company’s processing of children’s personal data. Based on press reports, the investigation… News Hunton Andrews Kurth Sep 2022 Default account settings
why this is here
children between the ages of 13 and 17 who were allowed to operate business or creator Instagram accounts

The business account default is a design issue, but the document does not mention Article 25.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 78 Guidance · all 48 Enforcement · all 27 Literature