Nature, scope, context and purpose of processing
These criteria have the same meaning as in Article 24(1) and Article 32(1). See therefore the commentary on Article 24 GDPR.
Risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing
The GDPR imposes the duty to perform a risk assessment in a number of its provisions like in Articles 24, 25, 32 and 35. The risk assessment should always be performed with regard to a given processing activity and is usually performed in connection with all the GDPR provisions demanding a risk assessment. Since the state of the art as well as the specific conditions of a processing activity regularly change, the risk assessment should be performed in regular intervals and when it comes to changes in the processing activity. For detailed remarks see therefore commentary on Article 24 GDPR.
For example: The provider of a newspaper offers high quality news articles against payment. The provider plans to give visitors of its website the alternative option to "pay" for the article by consenting to the processing of their personal data for behavioural advertising. According to the risk assessment foreseen in Article 25(1) GDPR the controller takes into account the particular risks associated with a lack of freely given consent, which constitutes a violation of the lawfulness principle and ends up implementing an additional free version without behavioural advertising[16] in order to provide an adequate alternative to the consent option.[17]
At the time of the determination of the means [...] and at the time of processing
Controllers must assess the implementation of appropriate measures "at the time of the determination of the means for processing" and "at the time of the processing itself". Therefore, the controller must already consider this obligation in the design stage of the processing activity - i.e. when it considers how the processing will be conducted and which mechanisms and tools it will use for the processing.[18] Hence, the privacy by design principle should be considered as early as possible in order to select appropriate processing mechanisms (e.g. software, hardware, processors). This also reduces the controller's risk of having to change these basic components late in the design stage due to to a lack of compliance with data protection principles.[19]
For example: A bank wants to implement a whistleblower tool for its employees. According to the privacy by design principle set out in Article 25(1) GDPR, the bank, as a controller, has to consider the requirements of the GDPR already during the design stage of the processing activity. Therefore, it has to consider how it can ensure compliance with data protection principles and protect the rights of data subjects (e.g. by choosing a GDPR compliant software by a third party and defining the strictly necessary information collected by whistleblower).
"Article 25(1) of the GDPR requires that the controller must, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures that are designed to implement data-protection principles in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of that regulation and protect the rights of data subjects.
[I]nasmuch as the operator of an online marketplace, such as the marketplace at issue in the main proceedings, knows or ought to know that, generally, advertisements containing sensitive data in terms of Article 9(1) of the GDPR, are liable to be published by user advertisers on its online marketplace, that operator, as controller in respect of that processing, is obliged, as soon as its service is designed, to implement appropriate technical and organisational measures in order to identify such advertisements before their publication and thus to be in a position to verify whether the sensitive data that they contain are published in compliance with the principles set out in Chapter II of that regulation. Indeed, as is apparent in particular from Article 25(1) of that regulation, the obligation to implement such measures is incumbent on it not only at the time of the processing, but already at the time of the determination of the means of processing and, therefore, even before sensitive data are published on its online marketplace in breach of those principles, that obligation being specifically intended to prevent such breaches."
CJEU - C-492/23 - Russmedia, margin number 89 and 97.
Obviously the obligations also apply throughout the live circle of the processing activity. Therefore, the controller must also consider the privacy by design principle when it considers any later changes in the processing activity.
This can lead to problems for processing activities that were already in place before the GDPR entered into force and that cannot easily be changed. However, Article 25 GDPR also applies to such preexisting systems. Controllers must re-asses their means of processing if the systems they use are outdated and fail to ensure compliance with the GDPR.[20] Because the state of the art continuously changes, updating systems will be a continuous and necessary practical component of adhering to the privacy by design principle during ongoing processing activities.[21]