Back to Feed
PolicySep 30, 2026

Article 25 GDPR

Article 25 GDPR mandates data protection by design and default for controllers.

Summary

Article 25 of the GDPR introduces the principles of data protection 'by design' and 'by default,' requiring controllers to implement appropriate technical and organizational measures to integrate data protection into systems and processing activities from the outset. This concept, though not new, emphasizes proactive privacy implementation. Controllers are responsible for ensuring these principles are applied not only during initial design but also throughout the lifecycle of processing activities, including when acquiring third-party services or updating existing systems. Approved certification mechanisms can serve as an element to demonstrate compliance.

Full text

Help Article 25 GDPR: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 15:05, 14 January 2026 view sourceLde (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators181 editsm ← Older edit Latest revision as of 15:23, 30 September 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators102 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 197: Line 197: ==Commentary====Commentary== Article 25 GDPR establishes the idea of data protection "by ''design'' and by ''default''”.<ref>The Data Protection Directive did not contain a similar provision. Although Article 17 DPD Recital 46 had a similar thrust, the focus in those provisions revolved mostly around security. See, ''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 573 (Oxford University Press 2020). However, these concepts were not new: privacy by design -and default was originally conceptualized in the 1990s by the Canadian Information and Privacy Commissioner of Ontario. They held that, in order to be effective, data protection must be implemented ''ex ante''. Hence, the controller must define the privacy requirements that need to be taken into account while engineering, and determine the default settings of the final product. See, ''Nolte, Werkmeister'', in Gola, Datenschutz-Grundverordnung, Article 25 GDPR, margin number 1 (C.H. Beck 2022, 3rd Edition).</ref> Accordingly, controllers must put in place appropriate technical and organisational measures that are designed to implement data protection principles. This means that when programming, designing and conceptualizing systems and programs, as well as when acquiring systems and services from third parties, the controller has to ensure that data protection is taken into account and that the principles of the GDPR are properly integrated into the processing activity.<ref>''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 576 (Oxford University Press 2020).</ref> The first paragraph describes the principles of data protection by ''design'' in more detail. The second paragraph expands on this by describing the principles of data protection by ''default''. The third paragraph explains that an approved certification mechanism, pursuant to Article 42, may be used as an element to demonstrate compliance.<ref>''Hartung'', in Kühling, Buchner, DS-GVO BDSG, Article 25, margin number 30 (C.H. Beck 2024, 4th Edition).</ref>Article 25 GDPR establishes the idea of data protection "by ''design'' and by ''default''”.<ref>The Data Protection Directive did not contain a similar provision. Although Article 17 DPD Recital 46 had a similar thrust, the focus in those provisions revolved mostly around security. See, ''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 573 (Oxford University Press 2020). However, these concepts were not new: privacy by design -and default was originally conceptualized in the 1990s by the Canadian Information and Privacy Commissioner of Ontario. They held that, in order to be effective, data protection must be implemented ''ex ante''. Hence, the controller must define the privacy requirements that need to be taken into account while engineering, and determine the default settings of the final product. See, ''Nolte'', in Gola, Datenschutz-Grundverordnung, Article 25 GDPR, margin number 1 (C.H. Beck 2026, 4th Edition).</ref> Accordingly, controllers must put in place appropriate technical and organisational measures that are designed to implement data protection principles. This means that when programming, designing and conceptualizing systems and programs, as well as when acquiring systems and services from third parties, the controller has to ensure that data protection is taken into account and that the principles of the GDPR are properly integrated into the processing activity.<ref>''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 576 (Oxford University Press 2020).</ref> The first paragraph describes the principles of data protection by ''design'' in more detail. The second paragraph expands on this by describing the principles of data protection by ''default''. The third paragraph explains that an approved certification mechanism, pursuant to Article 42, may be used as an element to demonstrate compliance.<ref>''Hartung'', in Kühling, Buchner, DS-GVO BDSG, Article 25, margin number 30 (C.H. Beck 2024, 4th Edition).</ref> The obligations under Article 25 are directed specifically at the controller ([[Article 4 GDPR|Article 4(7) GDPR]]) which remains accountable for fulfilling all legal obligations related to data processing. Processors are indirectly affected since, under [[Article 28 GDPR|Article 28(1) GDPR]], a controller shall only use processors providing the same standards as foreseen under Article 25 GDPR.<ref>Article 28(1) partially repeats the wording of Article 25(1): "''processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject''".</ref> However, ultimately the controller is responsible for the compliance of the processing carried out by their processors and sub-processors.<ref>EDPB, 'Guidelines 4/2019 on Article 25 Data Protection by Design and by Default', 20 October 2020 (Version 2.0), margin number 1 (available [https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-42019-article-25-data-protection-design-and_en here]).</ref>The obligations under Article 25 are directed specifically at the controller ([[Article 4 GDPR|Article 4(7) GDPR]]) which remains accountable for fulfilling all legal obligations related to data processing. Processors are indirectly affected since, under [[Article 28 GDPR|Article 28(1) GDPR]], a controller shall only use processors providing the same standards as foreseen under Article 25 GDPR.<ref>Article 28(1) partially repeats the wording of Article 25(1): "''processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject''".</ref> However, ultimately the controller is responsible for the compliance of the processing carried out by their processors and sub-processors.<ref>EDPB, 'Guidelines 4/2019 on Article 25 Data Protection by Design and by Default', 20 October 2020 (Version 2.0), margin number 1 (available [https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-42019-article-25-data-protection-design-and_en here]).</ref> Line 241: Line 241: [I]nasmuch as the operator of an online marketplace, such as the marketplace at issue in the main proceedings, knows or ought to know that, generally, advertisements containing sensitive data in terms of Article 9(1) of the GDPR, are liable to be published by user advertisers on its online marketplace, that operator, as controller in respect of that processing, is obliged, as soon as its service is designed, to implement appropriate technical and organisational measures in order to identify such advertisements before their publication and thus to be in a position to verify whether the sensitive data that they contain are published in compliance with the principles set out in Chapter II of that regulation. Indeed, as is apparent in particular from Article 25(1) of that regulation, the obligation to implement such measures is incumbent on it not only at the time of the processing,