Skip to content
EU GDPR · EU-GDPR-ART25-DP-BY-DESIGN

EU GDPR Article 25(1) and (2) — Data protection by design and by default

Build data-protection principles into the design of the processing, and make the privacy-protective configuration the default one

HIGHRequirementGovernanceBinding regulationIn forceEnforceable from 25 May 2018

Where this comes from

Provision: Article 25(1) and (2) — Data protection by design and by default

Instrument: EU General Data Protection Regulation (Regulation (EU) 2016/679)

Citation: Article 25, Regulation (EU) 2016/679

Text version: Regulation (EU) 2016/679 (GDPR), OJ L 119, 4.5.2016, p. 1 (CELEX 32016R0679)

Checked against the source: 2 September 2026

Read the official text ↗

Who it applies to

Personal data is processed (GDPR Art. 2(1)) — all of these:

  • Service processes personal data

…unless:

  • Art. 2(2)(c): the Regulation does not apply to processing of personal data 'by a natural person in the course of a purely personal or household activity'. Recital 18 keeps controllers or processors providing the means for such processing in scope. (GDPR Art. 2(2)(c))
  • Art. 25(1) is expressly proportionate: measures are owed 'taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and... (GDPR Art. 25(1))

Scope in the source's own terms

  • Art. 3(1)/(2): the processing is carried out in the context of the activities of an establishment in the Union, or relates to offering goods or services to, or monitoring the behaviour of, data subjects in the Union
  • Art. 2(1) read with Art. 4(1): the activity is the processing of personal data — any information relating to an identified or identifiable natural person
  • Art. 4(7): the duty binds the 'controller' — the person which, alone or jointly with others, determines the purposes and means of the processing (a processor's parallel duties sit in Art. 28/30(2))

What engineering work it implies

Sample acceptance criteria Landfall generates for this obligation:

  • Data-protection measures are decided when the means of processing are chosen, and that decision is recorded — not retrofitted at launch
  • Pseudonymisation and data minimisation are applied where they do not defeat the purpose, and the reasoning is recorded where they are not
  • By default, each field collected is tied to a specific purpose; a field with no purpose is removed rather than made optional
  • Default settings are the privacy-protective ones, and reaching a less protective setting requires an affirmative act by the person
  • By default, personal data is not made accessible to an indefinite number of people without the person's intervention (Art. 25(2), final sentence)

Evidence an auditor expects

  • Assessment documentDocument reviewReviewed at each design decision that changes the means of processing

    Data protection by design review, performed at the time the means of processing are determined

    A dated design review recording the Art. 25(1) factors actually weighed (state of the art, cost of implementation, nature/scope/context/purposes of the processing, and the risks of varying likelihood and severity for rights and freedoms), the technical and organisational measures adopted — such as pseudonymisation — to implement the data-protection principles effectively, and the safeguards integrated into the processing. Evidence must show the review happened at the DETERMINATION of the means, not retrospectively

  • Technical controlTechnical audit

    Data protection by default configuration evidence (Art. 25(2))

    Configuration evidence that by default only personal data necessary for each specific purpose is processed, covering all four dimensions Art. 25(2) names — the amount collected, the extent of processing, the period of storage, and accessibility — and specifically that by default personal data is not made accessible without the individual's intervention to an indefinite number of natural persons

  • Audit reportThird-party auditRecommended

    Approved certification relied on under Art. 25(3)

    Where an approved certification mechanism under Art. 42 is used as an element to demonstrate compliance, the certificate, its scope and validity period

Questions people ask

Does EU GDPR Article 25(1) and (2) — Data protection by design and by default apply to my service?
It applies when Service processes personal data. It does not apply where Art. 2(2)(c): the Regulation does not apply to processing of personal data 'by a natural person in the course of a purely personal or household activity'. Recital 18 keeps controllers or processors providing the means for such processing in scope. (GDPR Art. 2(2)(c)).
When does this become enforceable?
EU GDPR Article 25(1) and (2) — Data protection by design and by default is enforceable from 25 May 2018. Its current status is: in force.
What evidence does an auditor expect?
Data protection by design review, performed at the time the means of processing are determined; Data protection by default configuration evidence (Art. 25(2)); Approved certification relied on under Art. 25(3).

Find out whether this one lands on you

Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.

Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations