Data protection by default
Data protection by default means that, by default, only the personal data necessary for the specific purpose is processed and made accessible.
Data protection by default is part of data protection by design under Article 25 GDPR. A service, application or internal process should be configured from the outset so that its default settings limit processing to what is necessary for the specific purpose. This includes the amount of data, the extent of processing, the storage period and accessibility. The data protection glossary explains the related terms.
Article 25(2) GDPR also requires that, by default, personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons. A default publication setting, unnecessarily broad internal access or an unnecessarily long retention period can therefore conflict with the principle. The appropriate settings depend on the specific purpose, the risks and the technical and organisational measures in place.
Data protection by default is not a one-off choice in a setup wizard. Controllers should document the default values, review them regularly and adjust them when the purpose, product or risk changes. In practice, this connects data protection governance with specific areas such as marketing, cookies and tracking.
Legal framework
General orientation, not individual advice.
Discuss your data protection matter
Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000