[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRkVpDqHQoSCTzVT5NL7zbsX0ggzB0d3B9KqJkwgHqBc":3},{"article":4,"iocs":35},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":22},"1e67c596-bc9f-4e69-8b8a-b1787e0f7231","Article 25 GDPR","article-25-gdpr-4f5e8c","← Older revision Revision as of 15:23, 30 September 2026 (One intermediate revision by the same user not shown) Line 197: Line 197: ==Commentary== ==Commentary== Article 25 GDPR establishes the idea of data protection \"by ''design'' and by ''default''”. The Data Protection Directive did not contain a similar provision. Although Article 17 DPD Recital 46 had a similar thrust, the focus in those provisions revolved mostly around security. See, ''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 573 (Oxford University Press 2020). However, these concepts were not new: privacy by design -and default was originally conceptualized in the 1990s by the Canadian Information and Privacy Commissioner of Ontario. They held that, in order to be effective, data protection must be implemented ''ex ante''. Hence, the controller must define the privacy requirements that need to be taken into account while engineering, and determine the default settings of the final product. See, ''Nolte, Werkmeister'', in Gola, Datenschutz-Grundverordnung, Article 25 GDPR, margin number 1 (C.H. Beck 2022, 3rd Edition). Accordingly, controllers must put in place appropriate technical and organisational measures that are designed to implement data protection principles. This means that when programming, designing and conceptualizing systems and programs, as well as when acquiring systems and services from third parties, the controller has to ensure that data protection is taken into account and that the principles of the GDPR are properly integrated into the processing activity. ''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 576 (Oxford University Press 2020). The first paragraph describes the principles of data protection by ''design'' in more detail. The second paragraph expands on this by describing the principles of data protection by ''default''. The third paragraph explains that an approved certification mechanism, pursuant to Article 42, may be used as an element to demonstrate compliance. ''Hartung'', in Kühling, Buchner, DS-GVO BDSG, Article 25, margin number 30 (C.H. Beck 2024, 4th Edition). Article 25 GDPR establishes the idea of data protection \"by ''design'' and by ''default''”. The Data Protection Directive did not contain a similar provision. Although Article 17 DPD Recital 46 had a similar thrust, the focus in those provisions revolved mostly around security. See, ''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 573 (Oxford University Press 2020). However, these concepts were not new: privacy by design -and default was originally conceptualized in the 1990s by the Canadian Information and Privacy Commissioner of Ontario. They held that, in order to be effective, data protection must be implemented ''ex ante''. Hence, the controller must define the privacy requirements that need to be taken into account while engineering, and determine the default settings of the final product. See, ''Nolte'', in Gola, Datenschutz-Grundverordnung, Article 25 GDPR, margin number 1 (C.H. Beck 2026, 4th Edition). Accordingly, controllers must put in place appropriate technical and organisational measures that are designed to implement data protection principles. This means that when programming, designing and conceptualizing systems and programs, as well as when acquiring systems and services from third parties, the controller has to ensure that data protection is taken into account and that the principles of the GDPR are properly integrated into the processing activity. ''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 576 (Oxford University Press 2020). The first paragraph describes the principles of data protection by ''design'' in more detail. The second paragraph expands on this by describing the principles of data protection by ''default''. The third paragraph explains that an approved certification mechanism, pursuant to Article 42, may be used as an element to demonstrate compliance. ''Hartung'', in Kühling, Buchner, DS-GVO BDSG, Article 25, margin number 30 (C.H. Beck 2024, 4th Edition). The obligations under Article 25 are directed specifically at the controller ([[Article 4 GDPR|Article 4(7) GDPR]]) which remains accountable for fulfilling all legal obligations related to data processing. Processors are indirectly affected since, under [[Article 28 GDPR|Article 28(1) GDPR]], a controller shall only use processors providing the same standards as foreseen under Article 25 GDPR. Article 28(1) partially repeats the wording of Article 25(1): \"''processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject''\". However, ultimately the controller is responsible for the compliance of the processing carried out by their processors and sub-processors. EDPB, 'Guidelines 4\u002F2019 on Article 25 Data Protection by Design and by Default', 20 October 2020 (Version 2.0), margin number 1 (available [https:\u002F\u002Fwww.edpb.europa.eu\u002Four-work-tools\u002Four-documents\u002Fguidelines\u002Fguidelines-42019-article-25-data-protection-design-and_en here]). The obligations under Article 25 are directed specifically at the controller ([[Article 4 GDPR|Article 4(7) GDPR]]) which remains accountable for fulfilling all legal obligations related to data processing. Processors are indirectly affected since, under [[Article 28 GDPR|Article 28(1) GDPR]], a controller shall only use processors providing the same standards as foreseen under Article 25 GDPR. Article 28(1) partially repeats the wording of Article 25(1): \"''processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject''\". However, ultimately the controller is responsible for the compliance of the processing carried out by their processors and sub-processors. EDPB, 'Guidelines 4\u002F2019 on Article 25 Data Protection by Design and by Default', 20 October 2020 (Version 2.0), margin number 1 (available [https:\u002F\u002Fwww.edpb.europa.eu\u002Four-work-tools\u002Four-documents\u002Fguidelines\u002Fguidelines-42019-article-25-data-protection-design-and_en here]). Line 241: Line 241: [I]nasmuch as the operator of an online marketplace, such as the marketplace at issue in the main proceedings, knows or ought to know that, generally, advertisements containing sensitive data in terms of Article 9(1) of the GDPR, are liable to be published by user advertisers on its online marketplace, that operator, as controller in respect of that processing, is obliged, as soon as its service is designed, to implement appropriate technical and organisational measures in order to identify such advertisements before their publication and thus to be in a position to verify whether the sensitive data that they contain are published in compliance with the principles set out in Chapter II of that regulation. Indeed, as is apparent in particular from Article 25(1) of that regulation, the obligation to implement such measures is incumbent on it not only at the time of the processing, but already at the time of the determination of the means of processing and, therefore, even before sensitive data are published on its online marketplace in breach of those principles, that obligation being specifically intended to prevent such breaches.\"|CJEU - C-492\u002F23 - Russmedia|89 and 97}} Obviously the obligations also apply throughout the live circle of the processing activity. Therefore, the controller must also consider the privacy by design principle when it considers any later changes in the processing activity. [I]nasmuch as the operator of an online marketplace, such as the marketplace at issue in the main proceedings, knows or ought to know that, generally, advertisements containing sensitive data in terms of Article 9(1) of the GDPR, are liable to be published by user advertisers on its online marketplace, that operator, as controller in respect of that processing, is obliged, as soon as its service is designed, to implement appropriate technical and organisational measures in order to identify such advertisements before their publication and thus to be in a position to verify whether the sensitive data that they contain are published in compliance with the principles set out in Chapter II of that regulation. Indeed, as is apparent in particular from Article 25(1) of that regulation, the obligation to implement such measures is incumbent on it not only at the time of the processing, but already at the time of the determination of the means of processing and, therefore, even before sensitive data are published on its online marketplace in breach of those principles, that obligation being specifically intended to prevent such breaches.\"|CJEU - C-492\u002F23 - Russmedia|89 and 97}} Obviously the obligations also apply throughout the live circle of the processing activity. Therefore, the controller must also consider the privacy by design principle when it considers any later changes in the processing activity. This can lead to problems for processing activities that were already in place before the GDPR entered into force and that cannot easily be changed. However, Article 25 GDPR also applies to such preexisting systems. Controllers must re-asses their means of processing if the systems they use are outdated and fail to ensure compliance with the GDPR. EDPB, 'Guidelines 4\u002F2019 on Article 25 Data Protection by Design and by Default', 20 October 2020 (Version 2.0), marginal number 38 (available [https:\u002F\u002Fedpb.europa.eu\u002Four-work-tools\u002Four-documents\u002Fguidelines\u002Fguidelines-42019-article-25-data-protection-design-and_en here]). Because the state of the art continuously changes, updating systems will be a continuous and necessary practical component of adhering to the privacy by design principle during ongoing processing activities. ''Nolte, Werkmeister'', in Gola, Heckmann, Datenschutz-Grundverordnung, Article 25 GDPR, margin number 14 (C.H. Beck 2022, 3rd Edition). This can lead to problems for processing activities that were already in place before the GDPR entered into force and that cannot easily be changed. However, Article 25 GDPR also applies to such preexisting systems. Controllers must re-asses their means of processing if the systems they use are outdated and fail to ensure compliance with the GDPR. EDPB, 'Guidelines 4\u002F2019 on Article 25 Data Protection by Design and by Default', 20 October 2020 (Version 2.0), marginal number 38 (available [https:\u002F\u002Fedpb.europa.eu\u002Four-work-tools\u002Four-documents\u002Fguidelines\u002Fguidelines-42019-article-25-data-protection-design-and_en here]). Because the state of the art continuously changes, updating systems will be a continuous and necessary practical component of adhering to the privacy by design principle during ongoing processing activities. ''Werkmeister'', in Gola, Heckmann, Rost, DSGVO, Article 25 GDPR, margin number 14 (C.H. Beck 2026, 4th Edition). ==== Shall implement appropriate technical and organizational measures==== ==== Shall implement appropriate technical and organizational measures==== Line 284: Line 284: From the term \"safeguards\", it cannot be derived that any specific technical and organisational measures have to be integrated. Rather, the terms \"safeguards\" and \"technical and organisational measures\" are interchangeable. ''Baumgartner'', in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 24 GDPR, margin number 19 (C.H. Beck 2024, 3rd Edition). From the term \"safeguards\", it cannot be derived that any specific technical and organisational measures have to be integrated. Rather, the terms \"safeguards\" and \"technical and organisational measures\" are interchangeable. ''Baumgartner'', in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 24 GDPR, margin number 19 (C.H. Beck 2024, 3rd Edition). The controller's obligation to implement the necessary safeguards into the processing in order to meet the requirements of the GDPR can be understood as a responsibility to adopt internal policies and measures which ensure that the GDPR's obligations are taken into account whenever any new processing activity is planned or an existing processing activity is subject to any change. ''Nolte, Werkmeister'' in Gola, Heckmann, Datenschutz-Grundverordnung, Article 25 GDPR, margin number 20 (C.H. Beck 2022, 3rd Edition). The controller's obligation to implement the necessary safeguards into the processing in order to meet the requirements of the GDPR can be understood as a responsibility to adopt internal policies and measures which ensure that the GDPR's obligations are taken into account whenever any new processing activity is planned or an existing processing activity is subject to any change. ''Werkmeister'', in Gola, Heckmann, Rost, DSGVO, Article 25 GDPR, margin number 20 (C.H. Beck 2026, 4th Edition). Specifically, the controller has to integrate safeguards ensuring the protection of the rights of the data subjects. Therefore, the controller should not passively react to requests by data subjects, but should already have considered data subjects' rights and anticipate requests by data subjects in accordance with Chapter III of the GDPR. ''Nolte, Werkmeister'' in Gola, Heckmann, Datenschutz-Grundverordnung, Article 25 GDPR, margin number 19 (C.H. Beck 2022, 3rd Edition). {{Quote-example|A data broker collects personal data from a vast amount of data. It has to implement technical and organisational measures that ensure that e.g. (i) information is provided to the data subjects in accordance with [[Article 13 GDPR]] and [[Article 14 GDPR]] and (ii) even a vast amount of access requests can be efficiently answered without undue delay in accordance with [[Article 12 GDPR]] and [[Article 15 GDPR]].}} Specifically, the controller has to integrate safeguards ensuring the protection of the rights of the data subjects. Therefore, the controller should not passively react to requests by data subjects, but should already have considered data subjects' rights and anticipate requests by data subjects in accordance with Chapter III of the GDPR. ''Werkmeister'', in Gola, Heckmann, Rost, DSGVO, Article 25 GDPR, margin number 19 (C.H. Beck 2026, 4th Edition). {{Quote-example|A data broker collects personal data from a vast amount of data. It has to implement technical and organisational measures that ensure that e.g. (i) information is provided to the data subjects in accordance with [[Article 13 GDPR]] and [[Article 14 GDPR]] and (ii) even a vast amount of access requests can be efficiently answered without undue delay in accordance with [[Article 12 GDPR]] and [[Article 15 GDPR]].}} ===(2) Data protection by default=== ===(2) Data protection by default=== Line 348: Line 348: ===(3) Approved certification mechanism=== ===(3) Approved certification mechanism=== A controller has to be able to demonstrate compliance with the principles of privacy by design and by default (Article&nbsp;[[Article 5 GDPR|5(2)]] and [[Article 24 GDPR|24(1)]] GDPR). The last paragraph of Article&nbsp;25 offers the controller some guidance on how to demonstrate such compliance (similar to [[Article 24 GDPR#3|Article 24(3) GDPR]]). It states that an \"approved certification mechanism pursuant to [[Article 42 GDPR|Article 42]]\" ''may'' be used ''as an element'' to demonstrate compliance with the requirements set out in the first two paragraphs of the provision. Hence, just like in [[Article 24 GDPR#3|Article 24(3)]], it follows from the word \"element\" that such adherence only ''supports'' the assumption that the controller is compliant, and does not ''prove'' it. ''Nolte, Werkmeister'' in Gola, Heckmann, Datenschutz-Grundverordnung, Article 25 GDPR, margin number 19 (C.H. Beck 2022, 3rd Edition). A controller has to be able to demonstrate compliance with the principles of privacy by design and by default (Article&nbsp;[[Article 5 GDPR|5(2)]] and [[Article 24 GDPR|24(1)]] GDPR). The last paragraph of Article&nbsp;25 offers the controller some guidance on how to demonstrate such compliance (similar to [[Article 24 GDPR#3|Article 24(3) GDPR]]). It states that an \"approved certification mechanism pursuant to [[Article 42 GDPR|Article 42]]\" ''may'' be used ''as an element'' to demonstrate compliance with the requirements set out in the first two paragraphs of the provision. Hence, just like in [[Article 24 GDPR#3|Article 24(3)]], it follows from the word \"element\" that such adherence only ''supports'' the assumption that the controller is compliant, and does not ''prove'' it. ''Werkmeister'', in Gola, Heckmann, Rost, DSGVO, Article 25 GDPR, margin number 32 (C.H. Beck 2026, 4th Edition). {{Quote-EDPB|\"Even where a processing operation is awarded a certification in accordance with Article 42, the controller still has the responsibility to continuously monitor and improve compliance with the [Data Protection by Design and by Default]-criteria of Article 25.\"|EDPB, ‘Guidelines 4\u002F2019 on Article 25 Data Protection by Design and by Default’, 20 October 2020 (Version 2.0), margin number 91.|4=https:\u002F\u002Fwww.edpb.europa.eu\u002Four-work-tools\u002Four-documents\u002Fguidelines\u002Fguidelines-42019-article-25-data-protection-design-and_en}} {{Quote-EDPB|\"Even where a processing operation is awarded a certification in accordance with Article 42, the controller still has the responsibility to continuously monitor and improve compliance with the [Data Protection by Design and by Default]-criteria of Article 25.\"|EDPB, ‘Guidelines 4\u002F2019 on Article 25 Data Protection by Design and by Default’, 20 October 2020 (Version 2.0), margin number 91.|4=https:\u002F\u002Fwww.edpb.europa.eu\u002Four-work-tools\u002Four-documents\u002Fguidelines\u002Fguidelines-42019-article-25-data-protection-design-and_en}} Line 358: Line 358: [[Category:GDPR Articles]] [[index.php?title=Category:GDPR Articles]]","Article 25 of the GDPR introduces the principles of data protection 'by design' and 'by default,' requiring controllers to implement appropriate technical and organizational measures to integrate data protection into systems and processing activities from the outset. This concept, though not new, emphasizes proactive privacy implementation. Controllers are responsible for ensuring these principles are applied not only during initial design but also throughout the lifecycle of processing activities, including when acquiring third-party services or updating existing systems. Approved certification mechanisms can serve as an element to demonstrate compliance.","Article 25 GDPR mandates data protection by design and default for controllers.","Help Article 25 GDPR: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 15:05, 14 January 2026 view sourceLde (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators181 editsm ← Older edit Latest revision as of 15:23, 30 September 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators102 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 197: Line 197: ==Commentary====Commentary== Article 25 GDPR establishes the idea of data protection \"by ''design'' and by ''default''”.\u003Cref>The Data Protection Directive did not contain a similar provision. Although Article 17 DPD Recital 46 had a similar thrust, the focus in those provisions revolved mostly around security. See, ''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 573 (Oxford University Press 2020). However, these concepts were not new: privacy by design -and default was originally conceptualized in the 1990s by the Canadian Information and Privacy Commissioner of Ontario. They held that, in order to be effective, data protection must be implemented ''ex ante''. Hence, the controller must define the privacy requirements that need to be taken into account while engineering, and determine the default settings of the final product. See, ''Nolte, Werkmeister'', in Gola, Datenschutz-Grundverordnung, Article 25 GDPR, margin number 1 (C.H. Beck 2022, 3rd Edition).\u003C\u002Fref> Accordingly, controllers must put in place appropriate technical and organisational measures that are designed to implement data protection principles. This means that when programming, designing and conceptualizing systems and programs, as well as when acquiring systems and services from third parties, the controller has to ensure that data protection is taken into account and that the principles of the GDPR are properly integrated into the processing activity.\u003Cref>''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 576 (Oxford University Press 2020).\u003C\u002Fref> The first paragraph describes the principles of data protection by ''design'' in more detail. The second paragraph expands on this by describing the principles of data protection by ''default''. The third paragraph explains that an approved certification mechanism, pursuant to Article 42, may be used as an element to demonstrate compliance.\u003Cref>''Hartung'', in Kühling, Buchner, DS-GVO BDSG, Article 25, margin number 30 (C.H. Beck 2024, 4th Edition).\u003C\u002Fref>Article 25 GDPR establishes the idea of data protection \"by ''design'' and by ''default''”.\u003Cref>The Data Protection Directive did not contain a similar provision. Although Article 17 DPD Recital 46 had a similar thrust, the focus in those provisions revolved mostly around security. See, ''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 573 (Oxford University Press 2020). However, these concepts were not new: privacy by design -and default was originally conceptualized in the 1990s by the Canadian Information and Privacy Commissioner of Ontario. They held that, in order to be effective, data protection must be implemented ''ex ante''. Hence, the controller must define the privacy requirements that need to be taken into account while engineering, and determine the default settings of the final product. See, ''Nolte'', in Gola, Datenschutz-Grundverordnung, Article 25 GDPR, margin number 1 (C.H. Beck 2026, 4th Edition).\u003C\u002Fref> Accordingly, controllers must put in place appropriate technical and organisational measures that are designed to implement data protection principles. This means that when programming, designing and conceptualizing systems and programs, as well as when acquiring systems and services from third parties, the controller has to ensure that data protection is taken into account and that the principles of the GDPR are properly integrated into the processing activity.\u003Cref>''Bygrave'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 576 (Oxford University Press 2020).\u003C\u002Fref> The first paragraph describes the principles of data protection by ''design'' in more detail. The second paragraph expands on this by describing the principles of data protection by ''default''. The third paragraph explains that an approved certification mechanism, pursuant to Article 42, may be used as an element to demonstrate compliance.\u003Cref>''Hartung'', in Kühling, Buchner, DS-GVO BDSG, Article 25, margin number 30 (C.H. Beck 2024, 4th Edition).\u003C\u002Fref> The obligations under Article 25 are directed specifically at the controller ([[Article 4 GDPR|Article 4(7) GDPR]]) which remains accountable for fulfilling all legal obligations related to data processing. Processors are indirectly affected since, under [[Article 28 GDPR|Article 28(1) GDPR]], a controller shall only use processors providing the same standards as foreseen under Article 25 GDPR.\u003Cref>Article 28(1) partially repeats the wording of Article 25(1): \"''processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject''\".\u003C\u002Fref> However, ultimately the controller is responsible for the compliance of the processing carried out by their processors and sub-processors.\u003Cref>EDPB, 'Guidelines 4\u002F2019 on Article 25 Data Protection by Design and by Default', 20 October 2020 (Version 2.0), margin number 1 (available [https:\u002F\u002Fwww.edpb.europa.eu\u002Four-work-tools\u002Four-documents\u002Fguidelines\u002Fguidelines-42019-article-25-data-protection-design-and_en here]).\u003C\u002Fref>The obligations under Article 25 are directed specifically at the controller ([[Article 4 GDPR|Article 4(7) GDPR]]) which remains accountable for fulfilling all legal obligations related to data processing. Processors are indirectly affected since, under [[Article 28 GDPR|Article 28(1) GDPR]], a controller shall only use processors providing the same standards as foreseen under Article 25 GDPR.\u003Cref>Article 28(1) partially repeats the wording of Article 25(1): \"''processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject''\".\u003C\u002Fref> However, ultimately the controller is responsible for the compliance of the processing carried out by their processors and sub-processors.\u003Cref>EDPB, 'Guidelines 4\u002F2019 on Article 25 Data Protection by Design and by Default', 20 October 2020 (Version 2.0), margin number 1 (available [https:\u002F\u002Fwww.edpb.europa.eu\u002Four-work-tools\u002Four-documents\u002Fguidelines\u002Fguidelines-42019-article-25-data-protection-design-and_en here]).\u003C\u002Fref> Line 241: Line 241: [I]nasmuch as the operator of an online marketplace, such as the marketplace at issue in the main proceedings, knows or ought to know that, generally, advertisements containing sensitive data in terms of Article 9(1) of the GDPR, are liable to be published by user advertisers on its online marketplace, that operator, as controller in respect of that processing, is obliged, as soon as its service is designed, to implement appropriate technical and organisational measures in order to identify such advertisements before their publication and thus to be in a position to verify whether the sensitive data that they contain are published in compliance with the principles set out in Chapter II of that regulation. Indeed, as is apparent in particular from Article 25(1) of that regulation, the obligation to implement such measures is incumbent on it not only at the time of the processing,","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Article_25_GDPR&diff=53253&oldid=50429",null,"2026-09-30T15:23:38+00:00","2026-09-30T16:00:20.062986+00:00",7,[],"c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":18,"icon":13,"name":20,"slug":21},"Policy","policy",[23,28,33],{"category":24},{"id":25,"icon":13,"name":26,"slug":27},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":29},{"id":30,"icon":13,"name":31,"slug":32},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":34},{"id":18,"icon":13,"name":20,"slug":21},[]]