GDPR Article 25 sets out the obligation of data protection by design and by default, requiring controllers to embed privacy safeguards into processing systems and to minimise data collection from the outset.

Semantic Classification

Content

  • Article 25 requires that technical and organisational measures implementing data protection principles be designed into processing activities, and that by default only personal data necessary for each specific purpose is processed. It shifts privacy from an afterthought to a design constraint.
  • For immersive and connected systems that capture biometric and spatial data, the article frames how collection, retention and exposure should be limited. It connects directly to data minimisation and broader regulatory compliance duties.

Provenance