Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Article 25 (Privacy by Design)
Resources
🇫🇷 FR 🇬🇧 EN 🇳🇱 NL
EU Legal Reference⚖️ GDPR Regulatory Text⚖️ Binding Legal Force

Article 25 GDPR : Data Protection by Design and by Default Principles

Official EU Regulation (EU) 2016/679 legal analysis · Controlled official sources

⚡ In 30 seconds:

Article 25 GDPR requires controllers to integrate technical and organisational safeguards (minimisation, encryption, retention) at the system design stage (By Design) and to guarantee the most privacy-protective settings by default without requiring user intervention (By Default).

Data Protection by Design (Art. 25.1 GDPR)

In accordance with EDPB Guidelines 4/2019, the principle of Data Protection by Design requires the controller to embed GDPR compliance into the early architecture of systems, applications, and organizational processes.

This assessment must take into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of natural persons.

  • Application of pseudonymisation and encryption across data flows and storage layers;
  • Native integration of retention schedules and automated purging of expired records;
  • Granular access control based on the principle of least privilege.

Data Protection by Default (Art. 25.2 GDPR)

The principle of Data Protection by Default mandates that, by default, only personal data strictly necessary for each specific purpose of the processing are processed.

This applies to the amount of personal data collected, the extent of their processing, the period of their storage, and their accessibility (data must never be made accessible without human intervention to an indefinite number of natural persons).

Blockchain: Designing Architecture to Safeguard Rights

EDPB Final Guidelines 02/2025 reiterate that a blockchain is not, in itself, a processing operation, but that its intrinsic characteristics can make GDPR compliance challenging. The controller must therefore justify upstream the necessity of using such an architecture and document explored alternatives.

Personal data should not be stored directly on-chain when less intrusive alternatives exist. Off-chain architectures, minimised data, and technical mechanisms enabling the effective exercise of rights must be prioritized at the design stage.

  • Determine controllers, processors, or joint controllers according to actual network governance;
  • Prefer permissioned blockchains where this allows for clearer allocation of roles and access control;
  • Verify the strict necessity of a public ledger before making data accessible to an indefinite number of individuals;
  • Assess the impact of immutability on erasure and rectification rights, incorporating this analysis into the DPIA where required.

Verified Official Sources

⚖️ Binding Source
Regulation (EU) 2016/679 (GDPR) · CELEX: 32016R0679 · 2016-04-27

General Data Protection Regulation — EU Reference Legal Framework

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Guidelines 4/2019 on Article 25 Data Protection by Design and by Default

Privacy by Design & by Default, minimisation, sécurité dès la conception

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Guidelines 02/2025 on processing of personal data through blockchain technologies · 2026-07-07

Traitements de données au moyen de blockchains : nécessité de l'architecture, minimisation, données hors chaîne, gouvernance des rôles, protection dès la conception et effectivité des droits (version finale 2.0 adoptée le 7 juillet 2026).

Consult official source →

Associated Operational Micro-Tools

🔎
Art. 35 GDPR
DPIA Check (WP248 Criteria)

Check whether your project triggers mandatory DPIA requirements or meets the EDPB 9 high-risk criteria.

Launch interactive tool →

See Also in the Legal Framework

Article 5 GDPR Official Text

Article 5 GDPR: Cardinal Processing Principles & Accountability

Legal analysis of the cardinal principles in Article 5 GDPR: lawfulness, fairness, transparency, purpose limitation, dat...

View document
Article 35 GDPR Official Text

Article 35 GDPR : Criteria and Methodology of the DPIA

Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...

View document
Article 32 GDPR Official Text

Article 32 GDPR : Security of Processing Through Risk-Appropriate Measures

Article 32 GDPR: pseudonymisation and encryption, confidentiality, integrity, availability and resilience, prompt restor...

View document
EDPB Guidelines 02/2025 EDPB Doctrine

EDPB Guidelines 02/2025: Blockchain, Governance, and GDPR Compliance

EDPB Guidelines 02/2025 on blockchain technologies: Data Protection by Design and by Default (Art. 25), off-chain storag...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-28 Last modified: 2026-08-28

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice