GDPR Article 25: data protection by design and by default
Article 25 requires data protection by design and by default. A controller must build appropriate technical and organisational measures into processing when it decides the means and while it processes, and by default process only the personal data necessary for each specific purpose. Certification under Article 42 can help demonstrate compliance.
Applies to: Controllers subject to the GDPR that are designing, procuring or changing a system that processes personal data, including SaaS products, internal tools and third-party integrations.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanArticle 25 is the article that decides whether your GDPR programme is a design constraint or a document. It is short, it is specific about timing, and it is the provision most often satisfied on paper and missed in the product.
What Article 25(1) actually says
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of the Regulation and protect the rights of data subjects.
That is one sentence carrying four separate ideas.
It is a balancing test, not a fixed standard. State of the art and cost of implementation sit on one side; the nature of the processing and the risk to people sit on the other. A measure that is appropriate for a mailing list is not appropriate for health data, and the Regulation says so rather than leaving it to inference.
It attaches at design time. "At the time of the determination of the means for processing" is before any personal data exists in the system. This is the phrase that makes retrofitting a compliance failure in its own right, independent of whether the finished system is secure.
It also attaches during processing. The duty does not discharge at launch. A system that was appropriate in 2023 and has not been revisited is being measured against the state of the art in 2026.
It names its examples. Pseudonymisation is the named technique; data minimisation is the named principle. Neither is exhaustive, but a controller that has done neither has some explaining to do.
What Article 25(2) requires by default
The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed.
The text then tells you what "by default" covers, and the list is broader than most implementations treat it. The obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage, and their accessibility.
So a retention period is a by-default question, not only a retention-policy question. So is who inside your company can see a record.
Then comes the sentence with the sharpest edge: in particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
That is a rule about public-by-default. A profile that is visible to everyone unless the user changes a setting is the exact fact pattern the sentence describes. The individual's intervention has to make data more visible, never less.
Certification is evidence, not a shield
Article 25(3) says an approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2.
"An element" is doing deliberate work there. A certification helps you show your reasoning. It does not convert a non-compliant design into a compliant one, and it does not remove the supervisory authority's ability to look at the processing itself.
How this connects to the rest of the Regulation
Article 25 is the bridge between the principles in Article 5 and the security duty in Article 32. Article 5 tells you what data protection requires. Article 25 says build it in, at these two moments. Article 32 covers the security of the processing once it exists. And where processing is likely to result in a high risk, the Article 35 impact assessment is usually the exercise in which the Article 25 decisions get recorded.
If you are looking for the single artefact that demonstrates Article 25 compliance, it is usually the design record inside the impact assessment rather than a standalone document.
Next step
Article 25 is judged on decisions you made before launch, which is why it is worth knowing whether the GDPR applies to you before the next feature ships. The free 2-minute Obligation Scan tells you which privacy laws cover your business and what each one requires. See GDPR Article 32 for the security duty, GDPR Article 35 for impact assessments, and GDPR Article 5 for the principles Article 25 asks you to implement.
Compliance checklist
- Decide the lawful basis and the data set at design time, because Article 25(1) attaches when you determine the means of processing rather than when you go live.
- Default every new field, integration and share to off, since Article 25(2) covers the amount collected, the extent of processing, the storage period and accessibility.
- Check that no personal data is accessible to an indefinite number of people without the individual's own intervention, which Article 25(2) states as a specific outcome.
- Apply pseudonymisation and data minimisation where they are workable, as these are the two techniques the Article names.
- Record the balance you struck between the state of the art, the cost of implementation and the risk to individuals, because those factors are written into the standard and an assessment you cannot evidence is hard to defend.
- Treat an approved certification under Article 42 as supporting evidence rather than proof, which is what Article 25(3) says it is.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 25 (data protection by design and by default), consolidated text on EUR-Lex
- Regulation (EU) 2016/679 (GDPR), Article 42 (certification), consolidated text on EUR-Lex
- European Data Protection Board, Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
Last verified: 2026-09-01
Informational, not legal advice.