Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: SV

Artikel 25 Inbyggt dataskydd och dataskydd som standard


Summary What does Article 25 of the GDPR regulation say?

This article enshrines the principles of "data protection by design and by default," placing obligations on controllers to embed data protection into their processing activities from the outset.

Rather than treating privacy as an afterthought, controllers must consider and integrate appropriate technical and organisational measures at the point of designing their processing systems and throughout the processing itself.

The article also establishes that, by default, only the minimum personal data necessary should be processed, covering not just what is collected but also how broadly it is processed, how long it is stored, and who can access it.

It connects to Article 42, which allows certification mechanisms to serve as evidence of compliance.

Important points:

  • Controllers must build data protection into processing systems from the design stage, not after the fact.
  • Implement a "privacy by default" approach — ensuring that, without any action by the individual, only the minimum necessary personal data is processed and it is not made accessible to an indefinite number of people.
  • Adherence to an approved certification mechanism under Article 42 can be used as a means of demonstrating compliance with this article.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Med beaktande av den senaste utvecklingen, genomförandekostnader och behandlingens art, omfattning, sammanhang och ändamål samt riskerna, av varierande sannolikhetsgrad och allvar, för fysiska personers rättigheter och friheter ska den personuppgiftsansvarige, både vid fastställandet av vilka medel behandlingen utförs med och vid själva behandlingen, genomföra lämpliga tekniska och organisatoriska åtgärder – såsom pseudonymisering – vilka är utformade för ett effektivt genomförande av dataskyddsprinciper – såsom uppgiftsminimering – och för integrering av de nödvändiga skyddsåtgärderna i behandlingen, så att kraven i denna förordning uppfylls och den registrerades rättigheter skyddas.

    1. Den personuppgiftsansvarige ska genomföra lämpliga tekniska och organisatoriska åtgärder för att, i standardfallet, säkerställa att endast personuppgifter som är nödvändiga för varje specifikt ändamål med behandlingen behandlas. Den skyldigheten gäller mängden insamlade personuppgifter, behandlingens omfattning, tiden för deras lagring och deras tillgänglighet. Framför allt ska dessa åtgärder säkerställa att personuppgifter i standardfallet inte utan den enskildes medverkan görs tillgängliga för ett obegränsat antal fysiska personer.

    1. En godkänd certifieringsmekanism i enlighet med artikel 42 får användas för att visa att kraven i punkterna 1 och 2 i den här artikeln följs.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod