Guidelines On Data Protection By Design And By Default

The EDPB published its Guidelines 4/2019 on Article 25 - Data Protection by Design and by Default ("DPbDD") as adopted on 13 November 2019 (the "Guidelines"). The Guidelines give an in-depth analysis of the DPbDD requirements by reviewing one by one each condition provided by Article 25. They also focus on the controllers' accountability to demonstrate that appropriate measures and safeguards have been implemented to ensure that the data protection principles (transparency, lawfulness, fairness, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality) are effective in practice and protect the rights and freedoms of data subjects.

The EDPB reminds practitioners that DPbDD is a requirement for all controllers, independent of their size, including small local associations and multinational companies alike. However, the Guidelines may be useful to processors and technology providers who are interested in creating GDPR-compliant products and services for controllers, which can turn into a competitive advantage in the market. On the other hand, controllers are discouraged from using providers whose technology is not...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT