惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Google DeepMind News
Google DeepMind News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
Blog — PlanetScale
Blog — PlanetScale
腾讯CDC
A
About on SuperTechFans
Vercel News
Vercel News
I
InfoQ
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
人人都是产品经理
人人都是产品经理
S
SegmentFault 最新的问题
V
Visual Studio Blog
T
Tailwind CSS Blog
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
博客园 - 【当耐特】
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Microsoft Azure Blog
Microsoft Azure Blog
Apple Machine Learning Research
Apple Machine Learning Research
GbyAI
GbyAI
美团技术团队

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
What is privacy by design and by default? | iubenda
Carla Gonzalez Cidoncha · 2024-02-08 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

If you own a website, you have probably heard of privacy by design and privacy by default. These are fundamental GDPR principles that every website owner should know and implement. In this short guide, we explain how to comply with them.

privacy by design

In short

  • Article 25 of the GDPR
  • What does privacy by design mean?
  • What are the 7 principles of privacy by design?
  • Privacy by design: main requirements
  • What does privacy by default mean?
  • Privacy by default: main requirements

Article 25 of the GDPR

The controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organizational measures.

Article 25 of the General Data Protection Regulation introduces the concepts of privacy by design and privacy by default, which are essential for ensuring data security from the very beginning of a product or service.

According to the GDPR, every project must be initiated with privacy and data protection in mind to minimize any associated risks. This is part of the broader principle of accountability, for which you should always adopt a problem-prevention approach, rather than repairing the damage later.

For this reason, it’s recommended to start with a risk assessment to identify any vulnerabilities that could expose users to breaches. Article 25 also outlines the criteria that the data controller must consider in order to comply with the principle of privacy by design:

  • The nature of the processing, so how much it can affect users’ freedoms and rights.
  • The state of the art, meaning the technology available within the company and on the market.
  • The cost of implementation, which includes both monetary costs and the time and resources used.

What does privacy by design mean?

Privacy by design means integrating the protection of personal data from the design stage of a system or service. This proactive approach covers not only technology, but also business practices and operational decisions.

The goal is to minimize privacy risks from the outset, making data protection a core component and not a later addition.

What are the 7 principles of privacy by design?

The 7 principles of privacy by design were first defined by Ann Cavoukian, former Information and Privacy Commissioner for the Province of Ontario. The principles are as follows:

  1. Proactive not reactive: as we already said, your approach should be to prevent problems, not solve them later.
  2. Privacy as the default setting: make sure that the default settings are always the ones that ensure the highest degree of privacy protection.
  3. Privacy embedded into design: privacy considerations should be integrated into the design process at all stages.
  4. Full functionality – positive-sum, not zero-sum: privacy protections should not come at the expense of functionality or usability.
  5. End-to-end security: privacy protections should extend throughout the entire lifecycle of data, from collection to storage, use, and disposal.
  6. Visibility and transparency: organizations should be transparent about their data practices and policies.
  7. Respect for user privacy: privacy by design should prioritize the interests and preferences of individual users.

Privacy by design: main requirements

The main requirements of privacy by design include:

  • Data minimization: collect only the data strictly necessary for the service provided.
  • Purpose limitation: use collected data only for the stated purposes and not for any other purpose.
  • Built-in security: ensure that systems are designed with robust security measures to protect the data.
  • Transparency: be clear about how data are collected, used, and protected (to be specified in a privacy policy).
  • Proactive accountability: organizations must be proactive in preventing privacy risks.
💡 Here are a few practical examples

  • Ensure secure browsing with a SSL certificate and HTTPS transmission.
  • Keep data anonymized or encrypted.
  • Provide clear and accessible privacy notices for users.
  • Define organizational policies for access to sensitive information.
  • Back up the data.
  • Define an appropriate plan of action in case of data breach.

What does privacy by default mean?

Privacy by default means that the default settings of any service or product should be those that offer the highest degree of privacy. This implies that, without explicit user action, the collection and sharing of personal data should be limited to the minimum necessary.

Privacy by default: main requirements

The main requirements of privacy by default include:

  • Explicit consent: users must give explicit consent for any use of their data beyond basic functionality.
  • Ease of privacy management: privacy-related settings should be easily accessible and understandable to users.
  • Data protection from the start: personal data should be protected automatically without user intervention.
  • Minimizing data retention: keep personal data only as long as strictly necessary.

In conclusion, privacy by design and privacy by default are critical concepts in the digital age to effectively protect users’ personal information. This is not just about regulatory compliance, but about a cultural shift towards a more respectful and privacy-conscious approach to digital technologies.

Did you know that privacy by design also means compliance with privacy laws?

Here at iubenda, we have created a scanner to help you identify any compliance issues on your website!

Read also

About us

iubenda

Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.

www.iubenda.com