Privacy by Default
Privacy by Default means that an organisation's systems and services should automatically apply the most protective settings, using only the personal information genuinely needed for each specific purpose, without the individual having to take any action. In practice, this generally means default settings restrict how much personal data is collected, how it is used, and who can access it. It is one component of the broader data protection by design and by default obligation and is closely related to, but distinct from, Privacy by Design.
Privacy by Default (referred to as 'data protection by default' in the UK GDPR and by the European Commission and ICO) requires that, by default, an organisation processes only the personal data necessary to achieve each specific processing purpose, applying data minimisation as the baseline rather than an opt-in configuration. Per ICO guidance, safeguards must be in place by default to prevent personal data from being made available to an indefinite number of people without the individual's intervention, and the European Commission frames this as ensuring personal data is processed with the highest privacy protection by default. It is typically operationalised alongside Privacy by Design (data protection through technology design) as part of an accountability obligation, meaning organisations should be able to demonstrate, with evidence, that default settings enforce these limits. This entry defines the concept only; it does not cover the specific article references, the full scope of the data protection by design obligation, cross-border transfer mechanics, retention rules, or enforcement penalties, and treatment may differ across jurisdictions and regimes outside the UK GDPR and EU GDPR context described in the evidence.
Why it matters
Privacy by Default shifts the burden of protection away from individuals and onto the organisations that design and operate systems. Rather than expecting people to hunt through settings to restrict data collection or sharing, the most protective configuration should apply automatically. This matters because default settings strongly shape actual outcomes: where a service defaults to broad collection or wide visibility, the majority of personal data processing tends to reflect that default rather than any deliberate individual choice. By requiring data minimisation as the baseline, the principle aims to ensure that only the personal data genuinely necessary for each specific purpose is processed unless the individual actively chooses otherwise.
Under the UK GDPR and EU GDPR, this is part of an accountability obligation, which means organisations are expected to be able to demonstrate with evidence that their default settings enforce these limits. Stated intent is not sufficient; the expectation is that defaults can be shown to restrict how much personal data is collected, how it is used, and who can access it. The ICO specifically emphasises that safeguards must be in place by default to prevent personal data from being made available to an indefinite number of people without the individual's intervention, making default access controls and sharing settings a focal point of scrutiny.
Because it forms one component of the broader data protection by design and by default obligation, Privacy by Default is generally assessed alongside Privacy by Design rather than in isolation. Treatment can differ across jurisdictions and regimes outside the UK GDPR and EU GDPR context, so organisations operating internationally should not assume a single default configuration satisfies every applicable regime. This entry does not address specific article references, retention rules, cross-border transfer mechanics, or enforcement penalties.
Who it's relevant to
Inside Privacy by Default
Common questions
Answers to the questions practitioners most commonly ask about Privacy by Default.