Privacy
Glossary

Data protection by design

Data protection by design means that controllers build appropriate technical and organisational measures into a processing operation from the planning stage so that data protection principles and people’s rights are effectively protected.

In brief

Data protection by design is set out in Article 25(1) GDPR. Controllers must, both when determining the means for processing and during the processing itself, implement appropriate technical and organisational measures. These measures must effectively implement the data protection principles and protect the rights and freedoms of data subjects.

The appropriate measures depend, among other things, on the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing, and the risks to people. Examples include data minimisation, pseudonymisation, separated access rights, encryption and a deletion logic that reflects the purpose of the processing. The point is not to select one technology, but to design the whole processing operation in a suitable way.

Data protection by design is not a one-off assessment or a certificate. The decisions should fit the specific processing operation, data flows and safeguards and should be reviewed when the processing changes. It is distinct from data protection by default under Article 25(2) GDPR. By default, only the personal data necessary for each specific purpose should be processed, in the necessary amount, for the necessary period and with appropriate limits on accessibility.

The privacy compliance and governance topic provides a framework for implementation. The role check helps clarify responsibilities, while the processor checklist helps prepare technical and organisational requirements for service providers.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich