Privacy by design

Data protection glossary · 1 minute read

Privacy by design means building data protection into the technical and organisational design of systems, products and processes from the outset.

Content of the obligation

Controllers must take appropriate measures, both when determining the means of processing and during the processing itself, to implement the data protection principles effectively. The state of the art, the costs, the nature and purpose of the processing and the risks must be taken into account.

Typical measures include pseudonymisation, data minimisation, role and authorisation concepts and automatic deletion routines.

Background

The concept goes back to Ann Cavoukian, the former Information and Privacy Commissioner of the Canadian province of Ontario. The GDPR made it a binding obligation. Manufacturers are not directly bound by it, but according to the recitals they should be encouraged to take data protection into account.

Art. 25(1) GDPR
Data protection by design.
Recital 78 GDPR
Explanation of the measures and role of manufacturers.
Art. 25(3) GDPR
Certification as an element in demonstrating compliance.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.