UK GDPR Article 25: data protection by design and by default
Article 25(1A), inserted by the Data (Use and Access) Act 2025: “In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters.”
Article 25 asks controllers to build data protection in from the start and to use only the personal data they need. It is short, it was amended in 2025, and it sits behind questions about how privacy is designed into a product. This page quotes it and puts the ICO's guidance beside it.
Article 25, paragraph by paragraph
| Paragraph | Subject | What it requires | Who |
|---|---|---|---|
| 25(1) | By design | Appropriate technical and organisational measures, “both at the time of the determination of the means for processing and at the time of the processing itself” | Controllers |
| 25(1A)–(1B) | Children | For information society services likely to be accessed by children, take into account the “children’s higher protection matters” | Controllers of those services |
| 25(2) | By default | Only personal data “necessary for each specific purpose” — amount, extent, storage period and accessibility | Controllers |
| 25(3) | Certification | “An approved certification mechanism pursuant to Article 42” may demonstrate compliance | Controllers who choose it |
By design: Article 25(1)
“Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.”
The ICO's summary is simpler: “Data protection by design and by default is about considering data protection and privacy at the start of everything you do.”
The same balancing test as Article 32
State of the art, cost of implementation, the nature, scope, context and purposes of processing, and the risks to people — the same factors that set the level of security under Article 32. The difference is the object: Article 32 is about security, Article 25 about implementing all the data protection principles, such as data minimisation.
Children: Articles 25(1A) and 25(1B)
“In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters.” The ICO links the duty to its children's code and says that conforming to the code makes compliance with this duty likely. If your service is not likely to be accessed by children, these paragraphs do not add to Article 25(1).
DPIAs as part of design
“If your use of personal information is likely to result in a high risk to people’s rights and freedoms, you must complete a DPIA.” And more broadly: “It is good practice to complete a DPIA regardless of how you use personal information and whether you consider it high risk.” The ICO describes DPIAs as an important part of applying data protection by design and by default.
By default: Article 25(2)
“The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility.” And: “In particular, such measures shall ensure that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons.”
The ICO is clear this is a judgement, not a switch: “This doesn’t necessarily require you to switch everything to “off” by default.”
Processors and suppliers
“The data protection by design requirements don’t apply directly to processors.” But the controller remains responsible, and may use only processors that provide sufficient guarantees — which, the ICO says, applies to all aspects of data protection, including data protection by design. For a supplier, that is where Article 25 questions come from. See Article 28.
The ICO also lists a commercial reason to take it seriously: data protection by design can “increase your chances of meeting procurement requirements for regulated markets such as healthcare”. And a regulatory one: “if we’re considering whether to impose a fine or other regulatory intervention, we will take into account the technical and organisational measures you have put in place for data protection by design.”
Certification: Article 25(3)
“An approved certification mechanism pursuant to Article 42 may be used as a means of demonstrating compliance with the requirements set out in paragraphs 1 to 2 of this Article.” In its data protection by design guidance, the ICO names two approved schemes relevant to the children's duty:
| Scheme | What it does (ICO) |
|---|---|
| Age Check Certification Scheme (ACCS) | tests how age assurance products work |
| Age Appropriate Design Certification Scheme (AADCS) | provides criteria for the age appropriate design of online services |
An ISO 27001 certificate is not an Article 42 mechanism — see UK GDPR certification for why.
Where ISO 27001 fits (our reading)
ISO/IEC 27002, the guidance to ISO 27001's Annex A controls, has controls whose titles map onto design- stage work. We quote the titles from its contents; we have not quoted their text:
| Control | Title |
|---|---|
| 5.8 | Information security in project management |
| 5.34 | Privacy and protection of PII |
| 8.25 | Secure development life cycle |
| 8.27 | Secure system architecture and engineering principles |
Where those controls are in your ISMS scope and your Statement of Applicability, they are evidence of measures taken at the design stage. Article 25 covers more than security — data minimisation and purpose limitation are privacy principles an ISMS does not address by itself — which is the gap ISO/IEC 27701 is written to cover.
We do not give legal advice, audit or certify, and are paid the same fixed fee per enquiry whichever firm you use. The law is quoted from legislation.gov.uk and the guidance from ico.org.uk; the ISO section is our reading.
Where this fits
Common questions
What is data protection by design and by default?
“Data protection by design and by default is about considering data protection and privacy at the start of everything you do.” By design means building data protection into systems and processes from the design stage and throughout their life; by default means using only the personal data necessary for each specific purpose.
What does Article 25 of UK GDPR require?
That the controller implements appropriate technical and organisational measures, when deciding how to process and during processing, to implement the data protection principles effectively (Article 25(1)), and to ensure that by default only necessary personal data is processed (Article 25(2)). Since the Data (Use and Access) Act 2025 it also requires services likely to be accessed by children to take into account the children's higher protection matters.
Does data protection by default mean everything is switched off?
No. The ICO: “This doesn’t necessarily require you to switch everything to “off” by default.” It is about deciding what is appropriate for the processing and its risks.
Does Article 25 apply to processors?
Not directly. The ICO: “The data protection by design requirements don’t apply directly to processors.” But controllers must only use processors providing sufficient guarantees, and that includes data protection by design.
Do we need a DPIA for data protection by design?
Where processing is likely to be high risk, yes: “If your use of personal information is likely to result in a high risk to people’s rights and freedoms, you must complete a DPIA.” The ICO adds: “It is good practice to complete a DPIA regardless of how you use personal information and whether you consider it high risk.”
Is there a certification for data protection by design?
Article 25(3) allows an approved Article 42 certification mechanism to be used to demonstrate compliance. The ICO's guidance names two schemes in this context: the Age Check Certification Scheme and the Age Appropriate Design Certification Scheme. ISO 27001 is not an Article 42 mechanism.
How does ISO 27001 relate to data protection by design?
ISO/IEC 27002, the guidance to ISO 27001's controls, includes controls titled 'Privacy and protection of PII', 'Secure development life cycle' and 'Secure system architecture and engineering principles'. Where those are in your ISMS scope they are evidence of design-stage measures — our reading, not something Article 25 or the ICO says.
Sources cited on this page
- UK GDPR Article 25 (Data protection by design and by default), legislation.gov.uk
- ICO, Data protection by design and by default (Guide to accountability and governance)
- UK GDPR Article 28 (Processor), legislation.gov.uk
- ISO/IEC 27002:2022, official preview (contents, foreword, introduction, clauses 1–3), read first-hand
- ISO/IEC 27701:2025, Privacy information management systems — Requirements and guidance, official preview (foreword, introduction, clauses 1–3, contents), read first-hand
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
A customer asked how privacy is designed into your product?
Say what they asked and what your ISO 27001 scope covers, if you have one.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.