Article 25 of the GDPR: Data Protection by Design and by Default

Article 25 of the GDPR: Data Protection by Design and by Default

Article 25 of the GDPR Explained

The data controller must implement appropriate technical and organisational measures, by design, to comply with the principles of GDPR and protect the rights of individuals.

They must also ensure that, by default, only the data necessary for each purpose are collected, processed, stored, and accessible.

Why this article matters for your GDPR compliance?

Implementing data protection by design enables to reduce risks from the outset, improve transparency, and integrate GDPR compliance into information systems, products and services. This limits corrective costs and potential penalties.

How to Comply with Article 25 of the GDPR?

  • Incorporate the data protection dimension into all IT, marketing, HR projects, etc.
  • Apply a data minimisation policy: collect only what is strictly necessary.
  • Configure your tools and software for data protection by default (e.g., disabling optional features).
  • Conduct impact assessments for high-risk processing (PIA).

GDPR Article 25 Application Examples

  • A mobile application only requests the data strictly necessary for the operation of the service.
  • An online form only displays the mandatory fields for registration.
  • Marketing software automates the deletion of data after a defined period.

Related Resources

Accelerate Your Compliance in a Few Clicks

With our all-in-one solution, you can easily accelerate and ensure your compliance:

  • Automate your compliance with our GDPR software
  • Supported or outsourced by our DPO experts
  • Raise your teams' awareness with our GDPR training e-learning

Request a demo with an expert

Assess your situation in 15 minutes with our GDPR self-assessment, free and without obligation.

GDPR: Self-assess now