Privacy by Design & Privacy by Default

Last updated:
25.04.2024
The GDPR mandates data protection through technology design via privacy by design. Furthermore, privacy by default is intended to ensure data-friendly settings from the outset. In practice, this does not always work as intended.
Privacy by Design & Privacy by Default
Key Takeaways
  • Data protection by design and by default as defined in Article 25 of the GDPR.
  • Privacy by Design: Incorporating data protection into software development from the very beginning.
  • Privacy by Default: Ensuring data protection is the standard setting for services and devices.
  • Implementation is often inadequate, which can lead to heavy fines.
  • Certifications such as ISO 27001 demonstrate compliance with data protection requirements.

The terms Privacy by Design and Privacy by Default come up repeatedly in the context of the GDPR. They stand for data protection by design and by data protection by default. These principles offer many benefits to users, but for companies, they necessitate action – a requirement that is unfortunately often overlooked in practice.

Privacy by Design and Privacy by Default under the GDPR

Both terms are defined in Article 25 of the GDPR. This article deals exclusively with data protection by design and by default. The goal is to ensure that the personal data of data subjects is protected right from the start.

  • Privacy by Design: Article 25(1) of the GDPR refers to data protection by design . In concrete terms, this means that data protection aspects must be considered from the very beginning when developing any software or hardware capable of processing data. Privacy by Design therefore primarily concerns software development and can be implemented during the development stage through appropriate technical and organizational measures (TOM) (such as pseudonymization or anonymization).
  • Privacy by Default: Article 25(2) of the GDPR addresses this concept. It focuses on Data protection by default, which means privacy as the standard setting. The idea is that service, system, or device presets (factory settings) should be configured to be as privacy-friendly as possible. This is intended to protect users who may not be very tech-savvy and might not be able to adjust privacy settings to their preferences themselves.

Privacy by Design: Benefits and Approach

The Privacy by Design concept offers many advantages for both users and companies, as they can be confident when using new software or hardware that certain data protection standards were considered during its programming or manufacturing. For example, software should only collect data that is strictly necessary for a specific processing purpose. The processing of personal data should be limited to what is essential.

Although Article 25 of the GDPR is very application-oriented, implementing its requirements always requires developers to conduct a case-by-case assessment. Depending on how strictly the GDPR requirements have been implemented, it is possible to demonstrate compliance through certifications, such as ISO 27001 or other seals for high software quality, in accordance with Article 42 of the GDPR. If your company processes personal data, you should prioritize using certified software products that display such a seal.

Benefits of Privacy by Default

These requirements for privacy-friendly default settings are particularly relevant for internet users and website operators . In conjunction with the new cookie policy, users no longer have to laboriously adjust their settings while browsing to decide whether or not to allow tracking for advertising purposes. While users previously had to actively object to data usage (opt-out), it must now be disabled by default.

Unfortunately, many small and large companies have still not implemented these requirements. It is usually due to negligence that the cookie banner and tracking behavior are not adjusted. However, this constitutes a violation of the GDPR and can be subject to heavy fines. 

Implementing Privacy Principles in the Company

Internally, companies must also follow the Privacy Principles act. This means, firstly, that user data is protected. This extends to all areas of the company, for example from the website (cookie and tracking settings) to IT (this also includes employee data; the internal software and hardware landscape must be adapted to be data-protection-friendly accordingly), right through to applicant management (are the recruiting tools used designed to collect only necessary data?).

The aforementioned certifications for services, systems, or devices can provide assistance with correct internal implementation. Otherwise, the data protection officer is also responsible for implementing the privacy principles within the company. In addition, these basic principles can help you verify compliance with privacy principles in your company:

  • Privacy by Default: Is data protection the default setting for all services, systems, and devices?
  • Privacy by Design: Are data protection settings already integrated throughout, rather than being added on later?
  • Scope of functionality: Do data security and privacy settings hinder functionality? Compromises in the guaranteed scope of functionality are not permitted when non-essential personal data is to be collected.
  • End-to-end protection: Are all collected and stored data adequately protected throughout the entire company during their entire lifecycle? This applies regardless of whether the data belongs to applicants, employees, customers, or business partners.
  • Control security: Are you implementing privacy policies in a way that would withstand an audit by regulatory authorities?
  • Proactive action: Are all employees trained to identify potential data protection risks at an early stage?

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in