Fiche 41/54
Part 5 — Operational Obligations & Sanctions
Advanced
Reviewed 2026-08-23
Data Protection by Design & by Default (Art. 25)
Data Protection by Design & by Default (Art. 25)
⚡ In 30 seconds
Under Article 25, data protection cannot be an afterthought. Data protection by design (Art. 25.1) requires controllers to implement technical and organisational measures (e.g. pseudonymisation) at the time of system determination and processing. Data protection by default (Art. 25.2) requires that by default, only personal data necessary for each specific purpose are processed.
By Design (Architecture)
Proactive integration from the earliest conceptual design phase: field-level encryption, data segregation, automated pseudonymisation, audit logs.
By Default (Configuration)
Strict baseline settings: public profiles disabled by default, minimal data collection, non-essential tracking disabled, shortest retention applied.