Privacy
Glossary

Data protection by default

Data protection by default means that, by default, only the personal data necessary for the specific purpose is processed and made accessible.

In brief

Data protection by default is part of data protection by design under Article 25 GDPR. A service, application or internal process should be configured from the outset so that its default settings limit processing to what is necessary for the specific purpose. This includes the amount of data, the extent of processing, the storage period and accessibility. The data protection glossary explains the related terms.

Article 25(2) GDPR also requires that, by default, personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons. A default publication setting, unnecessarily broad internal access or an unnecessarily long retention period can therefore conflict with the principle. The appropriate settings depend on the specific purpose, the risks and the technical and organisational measures in place.

Data protection by default is not a one-off choice in a setup wizard. Controllers should document the default values, review them regularly and adjust them when the purpose, product or risk changes. In practice, this connects data protection governance with specific areas such as marketing, cookies and tracking.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich