implementing-data-protection-by-default
Installation
SKILL.md
Implementing Data Protection by Default
Overview
GDPR Article 25(2) requires that controllers implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. This obligation applies across four dimensions:
- Amount of personal data collected
- Extent of processing performed
- Period of storage
- Accessibility of personal data
The EDPB Guidelines 4/2019 on Article 25 clarify that "by default" means the strictest privacy settings apply automatically, without requiring any action from the data subject. The data subject should not need to take action to protect their privacy — the system does it for them.
The Four Dimensions of By-Default Protection
Dimension 1: Minimum Data Collection (Amount)
Principle: By default, collect only the data fields strictly necessary for the core service purpose. Additional data collection requires explicit opt-in.