Privacy by Design and by Default
Privacy by Design and by Default is the idea that organisations should build data protection into their products, services, and systems from the start, rather than adding it afterward. "By default" means that, without any action from the user, only the personal information genuinely needed for a specific purpose should be collected and processed, with the strongest privacy settings applied automatically. In the EU and UK, this is not just a good-practice concept but a legal requirement under data protection law.
Under the EU GDPR and the UK GDPR, data protection by design and by default is a binding accountability obligation requiring controllers to implement appropriate technical and organisational measures that embed data protection principles (such as data minimisation) into processing activities, and to do so both at the time of determining the means of processing and during the processing itself. "By design" refers to integrating data protection through technology and process design from the outset; "by default" requires that, absent user intervention, processing is limited to what is necessary for each specific purpose, applying the highest available privacy protection to the amount of data collected, the extent of processing, retention periods, and accessibility. This entry describes the legal obligation as framed in EU/UK data protection law and should be distinguished from the broader, voluntary seven-principle "Privacy by Design" framework originating in privacy engineering practice, which is conceptually related but not itself law. The precise statutory wording, article references, and enforcement expectations should be verified against the current authoritative text of the applicable regulation and the relevant supervisory authority's guidance, as interpretation and enforcement practice continue to evolve and application to specific circumstances requires professional judgement.
Why it matters
Data protection by design and by default shifts the moment at which privacy considerations enter a project. Rather than treating data protection as a compliance layer bolted on before launch, the obligation requires organisations to account for it when they determine how processing will occur and throughout the life of that processing. In the EU and UK, this is a binding accountability obligation on controllers under the GDPR and UK GDPR, not merely a matter of good practice, which means design decisions that ignore data minimisation or default to broad data collection can themselves constitute a breach even where no incident occurs.
The "by default" element carries particular weight because it addresses the reality that most users never change the settings they are given. The European Commission's guidance frames the expectation that, by default, personal data is processed with the highest privacy protection, and the ICO frames the requirement that use of personal information be limited to what is necessary to achieve each specific purpose. A product that collects more data than a purpose requires, retains it longer than needed, or exposes it more widely than necessary can fall short of the standard regardless of whether users are technically able to tighten those settings themselves.
Because interpretation and enforcement practice continue to evolve, and because the statutory obligation is distinct from the broader voluntary privacy engineering framework of the same name, organisations should treat the design and default requirements as fact-specific. What counts as "appropriate" measures depends on the nature of the processing, the risk to individuals, and the state of available technology, and application to particular circumstances requires professional judgement against the current authoritative text and supervisory authority guidance.
Who it's relevant to
Inside PbD
Common questions
Answers to the questions practitioners most commonly ask about PbD.

