EU GDPR Article 25(1) and (2) — Data protection by design and by default
Build data-protection principles into the design of the processing, and make the privacy-protective configuration the default one
Where this comes from
Provision: Article 25(1) and (2) — Data protection by design and by default
Instrument: EU General Data Protection Regulation (Regulation (EU) 2016/679)
Citation: Article 25, Regulation (EU) 2016/679
Text version: Regulation (EU) 2016/679 (GDPR), OJ L 119, 4.5.2016, p. 1 (CELEX 32016R0679)
Checked against the source: 2 September 2026
Who it applies to
Personal data is processed (GDPR Art. 2(1)) — all of these:
- Service processes personal data
…unless:
- Art. 2(2)(c): the Regulation does not apply to processing of personal data 'by a natural person in the course of a purely personal or household activity'. Recital 18 keeps controllers or processors providing the means for such processing in scope. (GDPR Art. 2(2)(c))
- Art. 25(1) is expressly proportionate: measures are owed 'taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and... (GDPR Art. 25(1))
Scope in the source's own terms
- Art. 3(1)/(2): the processing is carried out in the context of the activities of an establishment in the Union, or relates to offering goods or services to, or monitoring the behaviour of, data subjects in the Union
- Art. 2(1) read with Art. 4(1): the activity is the processing of personal data — any information relating to an identified or identifiable natural person
- Art. 4(7): the duty binds the 'controller' — the person which, alone or jointly with others, determines the purposes and means of the processing (a processor's parallel duties sit in Art. 28/30(2))
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Data-protection measures are decided when the means of processing are chosen, and that decision is recorded — not retrofitted at launch
- Pseudonymisation and data minimisation are applied where they do not defeat the purpose, and the reasoning is recorded where they are not
- By default, each field collected is tied to a specific purpose; a field with no purpose is removed rather than made optional
- Default settings are the privacy-protective ones, and reaching a less protective setting requires an affirmative act by the person
- By default, personal data is not made accessible to an indefinite number of people without the person's intervention (Art. 25(2), final sentence)
Evidence an auditor expects
- Assessment documentDocument reviewReviewed at each design decision that changes the means of processing
Data protection by design review, performed at the time the means of processing are determined
A dated design review recording the Art. 25(1) factors actually weighed (state of the art, cost of implementation, nature/scope/context/purposes of the processing, and the risks of varying likelihood and severity for rights and freedoms), the technical and organisational measures adopted — such as pseudonymisation — to implement the data-protection principles effectively, and the safeguards integrated into the processing. Evidence must show the review happened at the DETERMINATION of the means, not retrospectively
- Technical controlTechnical audit
Data protection by default configuration evidence (Art. 25(2))
Configuration evidence that by default only personal data necessary for each specific purpose is processed, covering all four dimensions Art. 25(2) names — the amount collected, the extent of processing, the period of storage, and accessibility — and specifically that by default personal data is not made accessible without the individual's intervention to an indefinite number of natural persons
- Audit reportThird-party auditRecommended
Approved certification relied on under Art. 25(3)
Where an approved certification mechanism under Art. 42 is used as an element to demonstrate compliance, the certificate, its scope and validity period
Questions people ask
- Does EU GDPR Article 25(1) and (2) — Data protection by design and by default apply to my service?
- It applies when Service processes personal data. It does not apply where Art. 2(2)(c): the Regulation does not apply to processing of personal data 'by a natural person in the course of a purely personal or household activity'. Recital 18 keeps controllers or processors providing the means for such processing in scope. (GDPR Art. 2(2)(c)).
- When does this become enforceable?
- EU GDPR Article 25(1) and (2) — Data protection by design and by default is enforceable from 25 May 2018. Its current status is: in force.
- What evidence does an auditor expect?
- Data protection by design review, performed at the time the means of processing are determined; Data protection by default configuration evidence (Art. 25(2)); Approved certification relied on under Art. 25(3).
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.