Privacy by Design and Default
Privacy by Design and Default is an approach in which privacy protections are built into products, services, and systems from the earliest stages of their development rather than added afterward. Under the 'by default' aspect, organizations are expected to configure their systems so that the strongest privacy settings apply automatically and only the personal data necessary for a specific purpose is used. It combines a design philosophy with, in some jurisdictions, a legal obligation.
Privacy by Design and Default refers to the practice of embedding data protection measures into the design and operation of processing activities and, by default, limiting the collection, use, retention, and accessibility of personal data to what is necessary for each specified purpose. The concept originated in the 1990s work of Dr. Ann Cavoukian, then Information and Privacy Commissioner of Ontario, who articulated seven foundational Privacy by Design principles as a voluntary framework. It was subsequently given explicit legal force in the EU General Data Protection Regulation (GDPR) and the UK GDPR, where 'data protection by design and by default' is set out as an obligation under Article 25; practitioners should note that outside these frameworks the term may function as a design principle or guidance rather than a binding requirement, and that its specific implementation obligations are scoped to those instruments and their applicable jurisdictions. As commonly defined, 'by design' addresses proactive integration of technical and organizational measures throughout the lifecycle, while 'by default' addresses configuration such that, absent user intervention, processing defaults to the highest level of privacy protection consistent with the stated purpose.
Why it matters
Privacy by Design and Default reframes data protection as an upstream engineering and governance concern rather than a compliance patch applied late in a system's lifecycle. When privacy measures are embedded from the earliest design stages, organizations reduce the likelihood of costly retrofits, minimize the volume of personal data exposed to potential misuse or breach, and are better positioned to demonstrate accountability. In frameworks such as the EU GDPR and the UK GDPR, this is more than good practice: 'data protection by design and by default' is set out as an explicit legal obligation under Article 25, meaning that in-scope organizations can face regulatory scrutiny for failing to build in appropriate technical and organizational measures.
The 'by default' dimension carries particular weight because it shifts the burden away from the individual. Rather than requiring users to hunt for and enable privacy protections, systems must be configured so that the most privacy-protective settings apply automatically, and so that only the personal data necessary for each specified purpose is collected and used. This directly counters common design patterns in which broad data collection is switched on by default and left to the user to disable.
For practitioners, the concept matters because it links a design philosophy—originating in the voluntary framework articulated in the 1990s by Dr. Ann Cavoukian, then Information and Privacy Commissioner of Ontario—to concrete, jurisdiction-specific legal duties. Its practical force depends heavily on context: within GDPR and UK GDPR it functions as a binding requirement, while in other jurisdictions or sectors it may operate as guidance or a design principle rather than an enforceable obligation. Treating it uniformly across all contexts is a frequent source of error.
Who it's relevant to
Inside PbD
Common questions
Answers to the questions practitioners most commonly ask about PbD.