Skip to main content
Category: Privacy Principles

Privacy by Default

Also known as: Data Protection by Default
Simply put

Privacy by Default means that an organisation's systems and services should automatically apply the most protective settings, using only the personal information genuinely needed for each specific purpose, without the individual having to take any action. In practice, this generally means default settings restrict how much personal data is collected, how it is used, and who can access it. It is one component of the broader data protection by design and by default obligation and is closely related to, but distinct from, Privacy by Design.

Formal definition

Privacy by Default (referred to as 'data protection by default' in the UK GDPR and by the European Commission and ICO) requires that, by default, an organisation processes only the personal data necessary to achieve each specific processing purpose, applying data minimisation as the baseline rather than an opt-in configuration. Per ICO guidance, safeguards must be in place by default to prevent personal data from being made available to an indefinite number of people without the individual's intervention, and the European Commission frames this as ensuring personal data is processed with the highest privacy protection by default. It is typically operationalised alongside Privacy by Design (data protection through technology design) as part of an accountability obligation, meaning organisations should be able to demonstrate, with evidence, that default settings enforce these limits. This entry defines the concept only; it does not cover the specific article references, the full scope of the data protection by design obligation, cross-border transfer mechanics, retention rules, or enforcement penalties, and treatment may differ across jurisdictions and regimes outside the UK GDPR and EU GDPR context described in the evidence.

Why it matters

Privacy by Default shifts the burden of protection away from individuals and onto the organisations that design and operate systems. Rather than expecting people to hunt through settings to restrict data collection or sharing, the most protective configuration should apply automatically. This matters because default settings strongly shape actual outcomes: where a service defaults to broad collection or wide visibility, the majority of personal data processing tends to reflect that default rather than any deliberate individual choice. By requiring data minimisation as the baseline, the principle aims to ensure that only the personal data genuinely necessary for each specific purpose is processed unless the individual actively chooses otherwise.

Under the UK GDPR and EU GDPR, this is part of an accountability obligation, which means organisations are expected to be able to demonstrate with evidence that their default settings enforce these limits. Stated intent is not sufficient; the expectation is that defaults can be shown to restrict how much personal data is collected, how it is used, and who can access it. The ICO specifically emphasises that safeguards must be in place by default to prevent personal data from being made available to an indefinite number of people without the individual's intervention, making default access controls and sharing settings a focal point of scrutiny.

Because it forms one component of the broader data protection by design and by default obligation, Privacy by Default is generally assessed alongside Privacy by Design rather than in isolation. Treatment can differ across jurisdictions and regimes outside the UK GDPR and EU GDPR context, so organisations operating internationally should not assume a single default configuration satisfies every applicable regime. This entry does not address specific article references, retention rules, cross-border transfer mechanics, or enforcement penalties.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads are generally responsible for advising on whether default configurations meet the data protection by default obligation and for ensuring the organisation can demonstrate, with evidence, that defaults limit data collection, use, and access to what is necessary for each specific purpose. They typically assess this alongside the wider data protection by design and by default obligation rather than as a standalone control.
Privacy Engineers and Product Designers
Those designing systems and services are the parties who translate Privacy by Default into concrete settings, ensuring the strictest privacy configuration applies automatically and that data minimisation is the baseline. This includes putting safeguards in place by default so that personal data is not made available to an indefinite number of people without the individual's intervention.
Compliance and Accountability Functions
Because Privacy by Default forms part of an accountability obligation under the UK GDPR and EU GDPR, compliance teams need to maintain demonstrable evidence that default settings enforce the required limits. Stated intent is not sufficient; the focus is on being able to show, in practice, how defaults restrict processing.
Organisations Operating Across Jurisdictions
Organisations processing personal data across multiple regimes should note that the treatment described here reflects the UK GDPR and EU GDPR context, where it is termed data protection by default. Treatment may differ across other jurisdictions and regimes, so a single default configuration should not be assumed to satisfy every applicable framework.

Inside Privacy by Default

Default Configuration of Processing
The principle that, without any active intervention by the individual, systems and services should process only the personal data necessary for each specific purpose. Under the EU GDPR and UK GDPR, this is framed alongside data protection by design as an accountability obligation on the controller. Treatment differs in regimes such as the CCPA/CPRA, HIPAA, and standards like ISO/IEC 27701 or the NIST Privacy Framework, which do not necessarily use identical terminology.
Data Minimization at the Default Level
By default, the amount of personal data collected, the extent of processing, the period of storage, and accessibility should be limited to what is necessary for the stated purpose. This applies before any user configuration and shifts the burden away from the individual having to opt out of excessive processing.
Limited Accessibility by Default
Personal data should not, by default, be made accessible to an indefinite number of people without the individual's action. This overlaps with information security access controls but remains a governance and data protection obligation rather than solely a security measure.
Controller Accountability
The obligation to implement privacy by default generally rests with the data controller, who must be able to demonstrate that appropriate measures are in place. A processor may be contractually required to support these measures, but accountability for the default posture typically sits with the controller. Demonstrable evidence, not stated intent, is required.
Relationship to Privacy by Design
Privacy by default is closely related to but distinct from privacy (data protection) by design. Design concerns embedding data protection into systems and processes throughout their lifecycle, while default concerns the out-of-the-box settings that apply absent user choice. The two are frequently addressed together but are not interchangeable.

Common questions

Answers to the questions practitioners most commonly ask about Privacy by Default.

Is privacy by default the same as privacy by design?
No. Privacy by design is the broader principle of embedding data protection considerations into systems, processes, and business practices throughout their lifecycle, while privacy by default is the narrower, specific requirement that, absent any user intervention, only the personal data necessary for a given purpose is processed. In the EU GDPR framing, both are set out together as related but distinct obligations on the controller. Privacy by default addresses the state of settings and configurations before a data subject makes any choice; privacy by design addresses the design methodology more generally. Treating the two as interchangeable is a common error.
Does turning on encryption or restricting access satisfy privacy by default?
Not by itself. Encryption and access controls are information security measures addressing confidentiality and integrity, whereas privacy by default is primarily a data minimisation concept concerned with the amount of personal data collected, the extent of processing, the retention period, and accessibility, by default and without user action. Security controls may form part of an overall approach but do not, on their own, discharge the default-minimisation obligation. It should also be noted that encrypting personal data does not render it non-personal; it generally remains personal data subject to applicable obligations.
How do we translate privacy by default into concrete product settings?
Generally, this means shipping features so that the least privacy-intrusive configuration is the pre-selected one: optional data collection is off unless the user opts in, sharing and visibility settings default to the narrowest audience, tracking or profiling that is not strictly necessary is not enabled by default, and retention periods are set to the minimum needed for the stated purpose. The controller should be able to justify each default against a specific processing purpose. This entry does not address the lawful basis required for any given processing, which must be assessed separately, nor cross-border transfer mechanics.
Who is responsible for implementing privacy by default within an organisation?
In the EU GDPR framing, the obligation rests with the data controller, who determines the purposes and means of processing. Where processing is carried out by a data processor, the controller typically imposes corresponding requirements through the arrangement governing that processing, but the accountability for ensuring default minimisation sits with the controller. Under governance frameworks, accountability requires demonstrable evidence, so responsibility in practice is usually shared operationally across product, engineering, and privacy functions, while remaining a controller obligation in law. This entry does not cover enforcement consequences for failure to implement.
How can we demonstrate that our defaults meet the requirement?
Accountability generally requires evidence rather than stated intent. Organisations typically maintain documentation showing the default configuration for each processing activity, the purpose it serves, and the reasoning for why that default represents the minimum necessary. Design decision records, configuration reviews, and testing that confirms defaults behave as documented can support this. Where a data protection impact assessment has been carried out, it may also record default-minimisation choices, though such an assessment is not always mandatory. This entry does not prescribe a specific format for that documentation.
Should privacy by default be reassessed after launch, and when?
Generally yes. Defaults should be revisited when purposes change, when new data elements or features are introduced, or when a change to configuration would alter the volume of personal data processed, its accessibility, or its retention. Because privacy by default concerns the state that applies before any user choice, changes to onboarding flows, new integrations, or third-party components can shift the effective default and warrant review. This entry does not specify retention periods themselves, which must be determined against the applicable purpose and any jurisdiction-specific rules.

Common misconceptions

Privacy by default is a universal legal requirement across all privacy regimes.
The concept is most explicitly articulated in the EU GDPR and UK GDPR. Other frameworks such as the CCPA/CPRA, HIPAA, ISO/IEC 27701, and the NIST Privacy Framework address related ideas differently or do not use the same terminology. Claims should be scoped to the specific instrument; treatment is not uniform across jurisdictions.
Privacy by default is satisfied by offering users privacy settings they can adjust.
The principle concerns the state of processing before any user action. Offering configurable settings does not satisfy the obligation if the default state still involves more collection, wider accessibility, or longer retention than necessary. The default itself must be the privacy-protective one.
Privacy by default is the same as privacy by design.
They are related but distinct. Privacy by design concerns embedding protections into systems and processes across their lifecycle, while privacy by default concerns the protective settings that apply absent any user choice. Meeting one does not automatically satisfy the other.

Best practices

Configure systems so that, out of the box, only the personal data necessary for each specific purpose is collected, processed, retained, and made accessible, without requiring the individual to take action.
Document the default settings and the necessity rationale for each processing purpose so the controller can demonstrate accountability with evidence rather than stated intent.
Scope your privacy-by-default claims to the applicable instrument, recognizing that the EU GDPR and UK GDPR framing differs from the CCPA/CPRA, HIPAA, ISO/IEC 27701, and the NIST Privacy Framework.
Treat privacy by default and privacy by design as complementary but separate obligations, addressing both explicitly rather than assuming one satisfies the other.
Where processing is carried out by a processor, use contractual terms to require support for privacy-by-default measures, while retaining controller accountability for the overall default posture.
Review default configurations for accessibility, retention periods, and the scope of collection whenever purposes or systems change, and record the review as demonstrable evidence.