What is “Privacy by Design” and how does “Privacy by Default” relate to it?
Privacy by Design embeds the data protection principles of the GDPR, such as purpose limitation, data minimisation, storage limitation, integrity and confidentiality, and transparency, in the design of systems, processes and products from the outset. The obligation and legal basis for Privacy by Design derive from Article 25 GDPR. Data protection must therefore already be taken into account during development and conception (“data protection by design and by default”).
Privacy by Default, also under Article 25 GDPR, is the concrete expression of this principle: default settings must be designed so that, by default, only the data required for the purpose are processed, in particular in terms of amount, scope, storage period and accessibility. In short: default means minimal.
When is Privacy by Design applied in practice?
Whenever you newly plan, further develop, roll out or materially change processing. Typical triggers include new products or features, new categories of data, such as location data or biometrics, new tracking or analytics setups, switching or onboarding a service provider, or roll-outs in new markets. In cases of high risk, such as profiling, special categories of data or systematic monitoring, a data protection impact assessment (DPIA) under Article 35 GDPR is generally required.
Why is Privacy by Design worthwhile: beyond compliance?
In practice, Privacy by Design does more than simply ensure legal compliance, it reduces risks, increases efficiency and strengthens users’ trust.
- Risk reduction: early controls prevent data protection incidents and reduce their impact.
- Efficiency: clear requirements from the outset avoid costly rework.
- Trust and UX: understandable information and fair defaults lead to higher acceptance.
- Demonstrability: lived Privacy-by-Design processes support accountability under Article 5(2) GDPR.
Privacy by Design across the lifecycle: what matters in each phase
- Discovery/idea: define the purpose, sketch data flows, assess necessity, conduct a DPIA pre-check, involve stakeholders from product, IT and Legal/DPO.
- Design: define data protection requirements as non-functional requirements: default settings, data minimisation, rights workflows, retention periods, roles and permissions, technical safeguards.
- Build and test: implement and test privacy controls, such as no personal data in logs or debugging, functioning erasure and export paths, and consent logic.
- Go-live: provide information notices, implement consent and cookie banners in compliance with the rules, taking TTDDG requirements for end-device cookies and trackers into account, and review access concepts.
- Operation/review: KPIs and monitoring, such as erasure rates and processing times for data subject rights, regular recertification of access rights, and DPIA review in the event of changes.
Free expertise in your e-mail inbox
All the important news on data protection, information security, AI and data strategy conveniently delivered to your e-mail inbox once a month - free of charge, of course. (Currently only available in German)
The 10 most important measures for Privacy by Design
The following overview shows the ten most important levers for implementing Privacy by Design pragmatically and in an auditable way in everyday practice.
1. Data minimisation and purpose limitation
Collect and process only the data required for the defined purpose. Remove “nice-to-have” fields and avoid free-text fields that generate unnecessary personal information; always check purpose compatibility for new uses.
2. Restrictive default settings: Privacy by Default
Features that disclose additional data, such as tracking, sharing or profile expansion, should be switched off by default. Users actively decide on opt-ins; make settings easy to find and understand.
3. Storage limitation with automation
Define retention periods for each category of data and set up automated erasure or anonymisation processes. Document and monitor exceptions, such as statutory retention requirements. No “just-in-case” storage.
4. Pseudonymisation and data separation
Store identity data, such as name and email address, separately from content and usage data, and link the two only via a randomly generated ID, or token, whose mapping is particularly well protected. Avoid raw IDs in events, reports or support screens.
5. Need-to-know access, least privilege and logging
Assign roles and permissions granularly and only to the extent necessary. Recertify regularly, use just-in-time access where appropriate and evaluate sensitive access.
6. Transparent, understandable user information: UX
Work with layered notices and just-in-time notices where data are generated. Avoid dark patterns; explain options clearly including the consequences of a decision.
7. Make data subject rights easy to use
Offer self-service, especially for access, rectification, erasure, objection and data portability with secure identity verification. Standardise internal processes to ensure deadlines are met.
8. Supplier management: processors
Review technical and organisational measures, data locations and subprocessors before onboarding and regularly thereafter. Contractually regulate erasure and exit, incident notifications and audit rights; have erasures confirmed in a demonstrable way.
9. Manage risks: DPIA and change control
Conduct a DPIA under Article 35 GDPR in cases of high risk and define specific mitigation measures. Repeat assessments in the event of material changes, such as new purposes, new sources or roll-outs, and document residual risks in a traceable way.
10. Use standards and best practices
Use established frameworks such as ISO 31700-1, Privacy by Design for consumer products and services, ISO/IEC 27701, Privacy Information Management, or the NIST Privacy Framework as guidance. They provide reusable controls and make audits easier but they do not replace GDPR obligations.
Industries and use cases where Privacy by Design is particularly important
Below you will find industries in which the scope and sensitivity of data are particularly high and where Privacy by Design therefore plays a central role.
- Health and MedTech, such as e-health, telemedicine and wearables: often special categories of data → high protection needs.
- Finance, InsurTech and scoring: profiling and partly automated decisions can have significant effects.
- Children, young people and EdTech, gaming and social: age-appropriate design and particularly strict defaults are essential.
- Mobility, connected cars and telematics: continuous location- and behaviour-based collection requires clear limits and short retention periods.
- Smart home, IoT and video: “always-on” sensors in private spaces, default to protection, not collection.
- AdTech, MarTech and social targeting: systematic tracking requires consent and very clear roles and responsibilities.
- HR tech and monitoring: employee data, potentially systematic monitoring, particular sensitivity and transparency are necessary.
Privacy by Design with external service providers: 10-point check
External service providers often process personal data on your behalf, as processors — which means technical and organisational risks shift outside your immediate environment. Structured vendor due diligence ensures that data protection by design and by default under Article 25 GDPR is also practised by the provider.
Example: you want to roll out a new CRM system. Before it goes live, you review, among other things, which categories of data are genuinely required, where the data are stored, which subprocessors are involved and how data will be demonstrably erased after the contract ends. Based on the results, you decide whether to approve the system, impose conditions or look for an alternative.
- Purpose and data categories: what is processed and for what purpose?
- Locations and subprocessors: where are systems located, and who is involved?
- Access: does support have access to production data? Under what conditions?
- Security: encryption, key management, incident processes.
- Data subject rights: does the service provider support access, erasure and export?
- Erasure concept: how and when are data erased or anonymised?
- Return/exit: how can you exit the contract cleanly, including data return?
- Auditability: which evidence and reports are available?
- Consent/TTDDG: does the use require end-device consent, for example for cookies or tracking?
- Change management: how are product changes communicated and assessed?
Common pitfalls and quick wins
Pitfalls: purposes that are too broad, retention periods that are too long, unclear responsibilities, personal data in logs or UTMs, non-transparent consent dialogues and missing evidence.
Quick wins: consistently minimise defaults, automate retention technically, check logs and analytics for personal data, establish clear roles and recertifications, provide understandable layered notices, and make the DPIA checklist a fixed step.
Fines for breaches of Privacy by Design under Article 25 GDPR
Breaches of Article 25 GDPR may be sanctioned under Article 83(4) GDPR with fines of up to EUR 10 million or 2% of worldwide annual turnover, whichever amount is higher. In practice, breaches of Privacy by Design or Privacy by Default are often assessed together with other breaches of obligations, such as transparency under Articles 12 and 13 GDPR or the principles under Article 5 GDPR in which case the upper limit of the most serious breach is decisive.
Example: in 2019, the Berlin Commissioner for Data Protection and Freedom of Information issued a fine notice of around EUR 14.5 million against Deutsche Wohnen SE. The background was an archive system without effective erasure options, as a result of which tenant data that were no longer required continued to be stored — a breach of Article 25(1) GDPR, Privacy by Design, as well as the principles under Article 5 GDPR. Note: the fine notice has since been overturned by the Berlin Regional Court. The proceedings are currently still ongoing.
What does this mean for you? Review default settings consistently, document Privacy-by-Design decisions, including a DPIA where necessary, and address transparency and erasure gaps early especially in offerings aimed at children or consumers.
Conclusion and next step
Privacy by Design is not an additional effort at the end, but a structured approach that reduces risks, makes compliance demonstrable and strengthens user trust. If you embed the lifecycle view, the 10 measures and clear roles outlined above, you create a robust foundation for new projects as well as for ongoing processes.
Would you like to prepare your team or a specific project for Privacy by Design? We are happy to support you with assessments, workshops or specific audits.
Your solution for the best data protection
Trust is the foundation of every good business relationship. Strengthen your relationships with customers by leveraging our expertise in data protection. This will give your company a strong competitive advantage, allowing you to focus fully on your business.