Data Protection by Design
What is Data Protection by Design?
The principle of integrating data protection measures into the design and development of business processes and IT systems from the outset. Required under GDPR Article 25 and considered best practice across all privacy regulations.
Terms that appear alongside data protection by design
Each of these is named in at least one of the same controls as data protection by design. The number is how many controls name both.
- data protection 19 shared controls
- gdpr 6 shared controls
- data minimisation 5 shared controls
- privacy by design 4 shared controls
- confidentiality 4 shared controls
- impact assessment 4 shared controls
- records of processing activities 4 shared controls
- data protection impact assessment 4 shared controls
Frameworks that govern data protection by design
What the standards actually require on data protection by design
Requirements naming data protection by design across 6 standards, quoted from the control text.
Data Protection by Design and by Default (GDPR Article 25) requires that, at the time of determining the means for processing and at the time of the processing itself, the controller implements appropriate technical and organisational measures designed to impl...
ENISA-DPE-1.1 · Data Protection by Design →Design security into systems, products and business practices from the outset rather than adding it afterwards, following recognised practice.
CCM-DSP-07 · Data Protection by Design and Default →Requires the controlling authority to implement data protection by design and by default and to meet general obligations for law-enforcement processing.
CZ-110-§32 · Zamerna a standardni ochrana osobnich udaju (data protection by design and default) →Requires providers of information society services likely to be accessed by children to consider how to protect children when designing data processing, reinforcing higher protection for children's data.
DUAA-P5-CHILDREN · Children's data protection by design (ISS) →Art.49 data protection by design and by default; Art.50 duty to destroy personal data at end of retention; Art.51 joint data controllers' joint and several responsibilities and transparency to data subjects.
ETH-PDPP-Art.49-51 · Data protection by design and by default; duty to destroy; joint controllers →Both at the time the means of processing are determined and at the time of the processing itself, implement appropriate technical and organisational measures such as pseudonymisation which are designed to implement the data protection principles, in particular...
GDPR-Art.25 · Data protection by design and by default →Questions people ask about data protection by design
What is Data Protection by Design?
Why is Data Protection by Design important for compliance?
Which compliance frameworks address Data Protection by Design?
Where can I learn more about Data Protection by Design?
See how Data Protection by Design applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.