EDPB 4/2019
Guidelines 4/2019 on Article 25 Data Protection by Design and by Default, version 2.0
What it covers
These guidelines interpret the Article 25 obligation of data protection by design and by default, analysing the design and default elements of Article 25(1) and (2), and explaining how to implement each of the Article 5 data protection principles through design and default measures, with additional sections on certification and enforcement.
Why it matters
It is the principal reference for translating the GDPR's abstract principles into concrete technical and organisational design choices when building or configuring systems that process personal data.
Refer to it when
- designing a new product or service that processes personal data
- reviewing default privacy settings
- advising engineering teams on embedding data protection principles
- assessing whether a legacy system meets Article 25 requirements
- considering certification as evidence of DPbDD compliance
Questions this document addresses
- What must a controller do to comply with data protection by design under Article 25(1)?
- What does data protection by default require regarding data minimisation?
- At what point in time must DPbDD be implemented?
- How should each Article 5 principle be implemented through design and default measures?
- How can certification under Article 25(3) demonstrate compliance?
Topics
- Data protection by design
- Lawful basis
- Data subject rights
- Certification & accreditation
Explains the Article 25 obligation to build data protection into processing from the outset and by default, with practical elements of effectiveness, key design and default criteria per data protection principle, and worked examples for controllers.
Mapped GDPR Articles
Reproduced from official EDPB publications for reference. Not legal advice.