Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 25 Data protection by design and by default
Summary What does Article 25 of the GDPR regulation say?
This article enshrines the principles of "data protection by design and by default," placing obligations on controllers to embed data protection into their processing activities from the outset.
Rather than treating privacy as an afterthought, controllers must consider and integrate appropriate technical and organisational measures at the point of designing their processing systems and throughout the processing itself.
The article also establishes that, by default, only the minimum personal data necessary should be processed, covering not just what is collected but also how broadly it is processed, how long it is stored, and who can access it.
It connects to Article 42, which allows certification mechanisms to serve as evidence of compliance.
Important points:
- Controllers must build data protection into processing systems from the design stage, not after the fact.
- Implement a "privacy by default" approach — ensuring that, without any action by the individual, only the minimum necessary personal data is processed and it is not made accessible to an indefinite number of people.
- Adherence to an approved certification mechanism under Article 42 can be used as a means of demonstrating compliance with this article.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
pseudonymisation
Definition
personal data