Data Protection by Design and by Default
Data protection by design and by default means building privacy considerations into systems, products, and processes from the outset rather than adding them later. By design, an organisation embeds data protection measures throughout the lifecycle of a project; by default, it limits the use of personal information to only what is necessary for each specific purpose. It is a way of making sure protective choices are the standard, not something individuals have to opt into.
Under the EU GDPR and the UK GDPR (originating in Article 25 GDPR), data protection by design and by default is an obligation on the controller to implement appropriate technical and organisational measures both at the time of determining the means of processing and during the processing itself. The 'by design' element requires that data protection principles be integrated into processing activities through measures such as those addressing data minimisation. The 'by default' element requires that only personal data necessary for each specific purpose be processed, and, per Article 25, that by default personal data are not made accessible without the individual's intervention to an indefinite number of persons. The obligation rests with the controller; it is generally treated as a demonstrable accountability requirement rather than a stated intention, and its concrete application depends on the state of the art, cost of implementation, and the nature, scope, context, and purposes of processing. Analogous requirements apply to processing for law enforcement purposes under the applicable law enforcement processing regime, where such measures must likewise be implemented by default. Note that DPbDD is distinct from, though it may draw on, information security controls; it is a governance and design obligation and does not by itself establish a lawful basis, satisfy transfer requirements, or determine retention periods. This entry does not address enforcement penalties, cross-border transfer mechanics, or the differing treatment of these concepts under regimes such as the CCPA and CPRA, HIPAA, ISO/IEC 27701, or the NIST Privacy Framework.
Why it matters
Data protection by design and by default reframes privacy from a feature bolted on late in development into a structural obligation that shapes how systems and processes are conceived. Under the EU GDPR and the UK GDPR, this is not aspirational guidance but a controller obligation originating in Article 25, and it is generally treated as a demonstrable accountability requirement. That distinction matters to practitioners: a stated commitment to privacy is insufficient, because the controller must be able to evidence the technical and organisational measures actually implemented, both when the means of processing are determined and during processing itself.
Who it's relevant to
Inside DPbDD
Common questions
Answers to the questions practitioners most commonly ask about DPbDD.