---
title: "Privacy by design and by default"
description: "The GDPR Article 25 duty to build data protection principles into processing through technical and organisational measures, and to process by default only the personal data each purpose needs."
canonical: https://aigovernanceengineer.com/glossary/privacy-by-design-and-by-default
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Privacy by design and by default

The GDPR Article 25 duty to build data protection principles into processing through technical and organisational measures, and to process by default only the personal data each purpose needs [1]. In an AI stack it shows up as filters, retention rules and access limits enforced as code.

- Developed in: [ch. 19, Minimisation, privacy by design and PETs](https://aigovernanceengineer.com/bok/privacy-and-ai#minimisation-privacy-by-design-and-pets)
- Chapters: [ch. 19, Privacy & AI](https://aigovernanceengineer.com/bok/privacy-and-ai)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-privacy-by-design-and-by-default

## Sources

[1] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 4(1), 4(5), 4(7), 4(8), 4(12), 4(14), 5, 6, 9, 12(3), 22, 25, 28(2) and 28(4), 30, 33, 35; Recital 26). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
