Article 25 GDPR : Data Protection by Design and by Default Principles
Article 25 GDPR requires controllers to integrate technical and organisational safeguards (minimisation, encryption, retention) at the system design stage (By Design) and to guarantee the most privacy-protective settings by default without requiring user intervention (By Default).
Data Protection by Design (Art. 25.1 GDPR)
In accordance with EDPB Guidelines 4/2019, the principle of Data Protection by Design requires the controller to embed GDPR compliance into the early architecture of systems, applications, and organizational processes.
This assessment must take into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of natural persons.
- Application of pseudonymisation and encryption across data flows and storage layers;
- Native integration of retention schedules and automated purging of expired records;
- Granular access control based on the principle of least privilege.
Data Protection by Default (Art. 25.2 GDPR)
The principle of Data Protection by Default mandates that, by default, only personal data strictly necessary for each specific purpose of the processing are processed.
This applies to the amount of personal data collected, the extent of their processing, the period of their storage, and their accessibility (data must never be made accessible without human intervention to an indefinite number of natural persons).
Blockchain: Designing Architecture to Safeguard Rights
EDPB Final Guidelines 02/2025 reiterate that a blockchain is not, in itself, a processing operation, but that its intrinsic characteristics can make GDPR compliance challenging. The controller must therefore justify upstream the necessity of using such an architecture and document explored alternatives.
Personal data should not be stored directly on-chain when less intrusive alternatives exist. Off-chain architectures, minimised data, and technical mechanisms enabling the effective exercise of rights must be prioritized at the design stage.
- Determine controllers, processors, or joint controllers according to actual network governance;
- Prefer permissioned blockchains where this allows for clearer allocation of roles and access control;
- Verify the strict necessity of a public ledger before making data accessible to an indefinite number of individuals;
- Assess the impact of immutability on erasure and rectification rights, incorporating this analysis into the DPIA where required.
Verified Official Sources
General Data Protection Regulation — EU Reference Legal Framework
Consult official source →Privacy by Design & by Default, minimisation, sécurité dès la conception
Consult official source →Traitements de données au moyen de blockchains : nécessité de l'architecture, minimisation, données hors chaîne, gouvernance des rôles, protection dès la conception et effectivité des droits (version finale 2.0 adoptée le 7 juillet 2026).
Consult official source →Associated Operational Micro-Tools
Check whether your project triggers mandatory DPIA requirements or meets the EDPB 9 high-risk criteria.
See Also in the Legal Framework
Article 5 GDPR: Cardinal Processing Principles & Accountability
Legal analysis of the cardinal principles in Article 5 GDPR: lawfulness, fairness, transparency, purpose limitation, dat...
Article 35 GDPR : Criteria and Methodology of the DPIA
Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...
Article 32 GDPR : Security of Processing Through Risk-Appropriate Measures
Article 32 GDPR: pseudonymisation and encryption, confidentiality, integrity, availability and resilience, prompt restor...
EDPB Guidelines 02/2025: Blockchain, Governance, and GDPR Compliance
EDPB Guidelines 02/2025 on blockchain technologies: Data Protection by Design and by Default (Art. 25), off-chain storag...