Article 25: Data protection by design and by defaultAI-relevant
Praxikon tracks Article 25 (Data protection by design and by default) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 25 govern?
Article 25 requires the controller to build data protection into a system or process from the start, rather than adding it afterwards. Already when determining the means, that is when designing or selecting for example software or an AI model, and also during the processing itself, you implement appropriate measures, such as pseudonymisation, that put the GDPR principles such as data minimisation into practice (paragraph 1). In addition, the default settings must ensure that only the data necessary for each specific purpose are processed: this covers the amount of data, the extent of processing, the storage period and accessibility (paragraph 2). By default, personal data must not be made accessible to an indefinite number of people without the individual's own intervention (paragraph 2). The article exists because you must be able to demonstrate compliance with the GDPR, and for that purpose internal policies and measures belong in the design and default settings themselves, such as data minimisation and pseudonymising data as soon as possible (recital 78).
Key term: Data protection by design and by default: privacy protection is built into the system itself, and the most restrictive setting is the default
Directly affects:controllerdata subject
Praxikon’s reading of the text and the recitals; the official text below prevails.
AI Act intersection
Data protection by design complements AI Act requirements for accuracy and cybersecurity (Art. 15). Both require built-in protection.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
Take data protection into account at the moment you design or procure a system, service or working method, not only once it is already running (paragraph 1). Choose measures such as pseudonymisation and data minimisation, weighing the state of the art, the cost of implementation and the risk to data subjects (paragraph 1). Set defaults so that, for each purpose, only the necessary data are collected, processed, stored and made accessible, and so that data are not visible to an indefinite number of people by default (paragraph 2).
Data Subject
You can expect a service to process by default only the data necessary for its purpose, and to not make your data visible to an indefinite number of people without your own action (paragraph 2).
Compliance checklist
Related recitals
Cross-references
Frequently asked questions
Connections
What connects to Article 25 GDPR
Themes where this returns
The counterpart in the other law
Case law
- Russmedia: an online marketplace operator is controller for personal data in adverts and must check before publication
2025-12-02 · final, Hof van Justitie van de EU (Grote kamer), X tegen Russmedia Digital SRL en Inform Media Press SRL
Guidelines
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
2020-10-20 · final, European Data Protection Board (EDPB)
- Guidelines 02/2025 on processing of personal data through blockchain technologies
2026-07-07 · final, European Data Protection Board (EDPB)
- Guidelines 01/2025 on Pseudonymisation
2025-01-16 · adopted, European Data Protection Board (EDPB)
Legislation in motion
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper