iso27001partnersUK certification, costed Get a cost estimate

UK GDPR Article 25: data protection by design and by default

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 8 min read
5 primary sources cited on this page. How we check what is on this site
Changed in 2025 Children’s higher protection matters

Article 25(1A), inserted by the Data (Use and Access) Act 2025: “In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters.”

Article 25 asks controllers to build data protection in from the start and to use only the personal data they need. It is short, it was amended in 2025, and it sits behind questions about how privacy is designed into a product. This page quotes it and puts the ICO's guidance beside it.

Article 25, paragraph by paragraph

UK GDPR Article 25: what each paragraph requires, and of whom
ParagraphSubjectWhat it requiresWho
25(1)By designAppropriate technical and organisational measures, “both at the time of the determination of the means for processing and at the time of the processing itself”Controllers
25(1A)–(1B)ChildrenFor information society services likely to be accessed by children, take into account the “children’s higher protection matters”Controllers of those services
25(2)By defaultOnly personal data “necessary for each specific purpose” — amount, extent, storage period and accessibilityControllers
25(3)Certification“An approved certification mechanism pursuant to Article 42” may demonstrate complianceControllers who choose it

By design: Article 25(1)

“Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.”

The ICO's summary is simpler: “Data protection by design and by default is about considering data protection and privacy at the start of everything you do.”

The same balancing test as Article 32

State of the art, cost of implementation, the nature, scope, context and purposes of processing, and the risks to people — the same factors that set the level of security under Article 32. The difference is the object: Article 32 is about security, Article 25 about implementing all the data protection principles, such as data minimisation.

Children: Articles 25(1A) and 25(1B)

“In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters.” The ICO links the duty to its children's code and says that conforming to the code makes compliance with this duty likely. If your service is not likely to be accessed by children, these paragraphs do not add to Article 25(1).

DPIAs as part of design

“If your use of personal information is likely to result in a high risk to people’s rights and freedoms, you must complete a DPIA.” And more broadly: “It is good practice to complete a DPIA regardless of how you use personal information and whether you consider it high risk.” The ICO describes DPIAs as an important part of applying data protection by design and by default.

By default: Article 25(2)

“The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility.” And: “In particular, such measures shall ensure that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons.”

The ICO is clear this is a judgement, not a switch: “This doesn’t necessarily require you to switch everything to “off” by default.”

Processors and suppliers

“The data protection by design requirements don’t apply directly to processors.” But the controller remains responsible, and may use only processors that provide sufficient guarantees — which, the ICO says, applies to all aspects of data protection, including data protection by design. For a supplier, that is where Article 25 questions come from. See Article 28.

The ICO also lists a commercial reason to take it seriously: data protection by design can “increase your chances of meeting procurement requirements for regulated markets such as healthcare”. And a regulatory one: “if we’re considering whether to impose a fine or other regulatory intervention, we will take into account the technical and organisational measures you have put in place for data protection by design.”

Certification: Article 25(3)

“An approved certification mechanism pursuant to Article 42 may be used as a means of demonstrating compliance with the requirements set out in paragraphs 1 to 2 of this Article.” In its data protection by design guidance, the ICO names two approved schemes relevant to the children's duty:

Certification schemes named in the ICO's data protection by design guidance
SchemeWhat it does (ICO)
Age Check Certification Scheme (ACCS)tests how age assurance products work
Age Appropriate Design Certification Scheme (AADCS)provides criteria for the age appropriate design of online services

An ISO 27001 certificate is not an Article 42 mechanism — see UK GDPR certification for why.

Where ISO 27001 fits (our reading)

ISO/IEC 27002, the guidance to ISO 27001's Annex A controls, has controls whose titles map onto design- stage work. We quote the titles from its contents; we have not quoted their text:

ISO/IEC 27002:2022 controls relevant to design-stage measures (titles from its contents)
ControlTitle
5.8Information security in project management
5.34Privacy and protection of PII
8.25Secure development life cycle
8.27Secure system architecture and engineering principles

Where those controls are in your ISMS scope and your Statement of Applicability, they are evidence of measures taken at the design stage. Article 25 covers more than security — data minimisation and purpose limitation are privacy principles an ISMS does not address by itself — which is the gap ISO/IEC 27701 is written to cover.

We do not give legal advice, audit or certify, and are paid the same fixed fee per enquiry whichever firm you use. The law is quoted from legislation.gov.uk and the guidance from ico.org.uk; the ISO section is our reading.

Where this fits

Common questions

What is data protection by design and by default?

“Data protection by design and by default is about considering data protection and privacy at the start of everything you do.” By design means building data protection into systems and processes from the design stage and throughout their life; by default means using only the personal data necessary for each specific purpose.

What does Article 25 of UK GDPR require?

That the controller implements appropriate technical and organisational measures, when deciding how to process and during processing, to implement the data protection principles effectively (Article 25(1)), and to ensure that by default only necessary personal data is processed (Article 25(2)). Since the Data (Use and Access) Act 2025 it also requires services likely to be accessed by children to take into account the children's higher protection matters.

Does data protection by default mean everything is switched off?

No. The ICO: “This doesn’t necessarily require you to switch everything to “off” by default.” It is about deciding what is appropriate for the processing and its risks.

Does Article 25 apply to processors?

Not directly. The ICO: “The data protection by design requirements don’t apply directly to processors.” But controllers must only use processors providing sufficient guarantees, and that includes data protection by design.

Do we need a DPIA for data protection by design?

Where processing is likely to be high risk, yes: “If your use of personal information is likely to result in a high risk to people’s rights and freedoms, you must complete a DPIA.” The ICO adds: “It is good practice to complete a DPIA regardless of how you use personal information and whether you consider it high risk.”

Is there a certification for data protection by design?

Article 25(3) allows an approved Article 42 certification mechanism to be used to demonstrate compliance. The ICO's guidance names two schemes in this context: the Age Check Certification Scheme and the Age Appropriate Design Certification Scheme. ISO 27001 is not an Article 42 mechanism.

How does ISO 27001 relate to data protection by design?

ISO/IEC 27002, the guidance to ISO 27001's controls, includes controls titled 'Privacy and protection of PII', 'Secure development life cycle' and 'Secure system architecture and engineering principles'. Where those are in your ISMS scope they are evidence of design-stage measures — our reading, not something Article 25 or the ICO says.

Sources cited on this page

  1. UK GDPR Article 25 (Data protection by design and by default), legislation.gov.uk
  2. ICO, Data protection by design and by default (Guide to accountability and governance)
  3. UK GDPR Article 28 (Processor), legislation.gov.uk
  4. ISO/IEC 27002:2022, official preview (contents, foreword, introduction, clauses 1–3), read first-hand
  5. ISO/IEC 27701:2025, Privacy information management systems — Requirements and guidance, official preview (foreword, introduction, clauses 1–3, contents), read first-hand

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

A customer asked how privacy is designed into your product?

Say what they asked and what your ISO 27001 scope covers, if you have one.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now