77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Art. 25 GDPR: data protection by design is a duty of the controller, and it applies at two moments
Data Protection & Privacy

Art. 25 GDPR: data protection by design is a duty of the controller, and it applies at two moments

21 September 20269 min readBy CIVAC Redaktion
CIVAC

Art. 25(1) GDPR binds the controller “both at the time of the determination of the means for processing and at the time of the processing itself”. This article takes that two-moment structure literally, explains why a certification under paragraph 3 is only an element, and shows from Art. 39(1)(a) and (b) where the person sits who actually does this work.

The addressee: the controller

Art. 25(1) GDPR opens with a long balancing clause and then arrives at the subject of the sentence: “the controller shall … implement appropriate technical and organisational measures”. Not the manufacturer of the software, not the development team, not a testing tool. Whoever is responsible for the processing owes the design. That is the first point at which the term “data protection by design” blurs in practice: it gets described as a property of a product, whereas the Regulation frames it as a duty of an organisation.

The two moments, in the text's own words

The decisive part of paragraph 1 reads: the controller shall implement the measures “both at the time of the determination of the means for processing and at the time of the processing itself”. The measures are to be “designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects”.

The first moment is the determination of the means. That is the point at which it is decided which system, which fields, which interfaces and which storage locations a processing operation will have. Anyone who has not yet taken measures at that point, because the system is still being built or procured, is under the duty precisely then. The second moment is the processing itself. That is ongoing operation, and it lasts as long as processing takes place. A measure that was right when the means were determined must remain appropriate in operation.

The “both … and” is therefore not redundancy but the structure of the duty. A check before first use satisfies the first moment. It does not satisfy the second. And an operation that was tidied up afterwards satisfies the second moment but does not explain what happened at the first. Anyone who wants to evidence Art. 25 needs something in the file for both moments.

Paragraph 2: defaults, in four dimensions

Paragraph 2 specifies part of the duty. The controller shall implement measures “for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed”. The second sentence names four dimensions: “the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility”. The third sentence sets a limit that can be tested: by default, personal data must not be “made accessible without the individual's intervention to an indefinite number of natural persons”.

Paragraph 3: a certification is an element, not the proof

Paragraph 3 reads: “An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.” Three limitations sit in that sentence. It must be an approved mechanism under Art. 42, not any seal. It “may” be used, not “shall be deemed”. And it is “an element”, not the demonstration.

Art. 42(4) GDPR says it even more plainly: “A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation”. Under Art. 42(7), a certification is issued for a maximum period of three years. Anyone relying on a certification as evidence for Art. 25 therefore holds an element with an expiry date that leaves their own responsibility untouched.

The same applies, by extension, to every form of external confirmation that is not an approved certification: an audit report, a vendor's attestation, an automated finding. They can sit in the file and support the controller's decision. They do not replace it, because Art. 25(1) assigns the decision to the controller.

Where the person sits: Art. 39(1)(a) and (b)

Art. 25 says who carries the duty. Art. 39 says who inside the organisation makes sure it is recognised and complied with. Under Art. 39(1)(a), the data protection officer's task is “to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation”. Under point (b), it is “to monitor compliance with this Regulation … including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits”.

Applied to the two moments of Art. 25: at the time the means are determined, point (a) applies, advice before the decision is made. Art. 38(1) requires for this that the data protection officer “is involved, properly and in a timely manner, in all issues which relate to the protection of personal data”. At the time of the processing itself, point (b) applies, monitoring together with responsibilities, training and audits. The person who carries Art. 25 in operation is therefore not a new invention. It is the data protection officer with the first two of their statutory tasks.

What this puts in the file

  • For the first moment: a dated note that the data protection officer advised before the means were determined, with the measures taken and the four dimensions of paragraph 2.
  • For the second moment: recurring reviews of the defaults in ongoing operation, with owner, date and result.
  • For every certification or external confirmation: filed as an element, with its validity date, and the controller's own assessment beside it.
  • For every change of the means: the first moment starts again.

In the CIVAC workspace exactly that runs as tasks and audits of the data protection officer role: a task before a system is introduced, a recurring audit in operation, and for both a history showing who advised when and who reviewed when. The workspace does not design technology. It records that the controller did, and when.

Where this article ends

Which measures are “appropriate” in your case within the meaning of Art. 25(1) GDPR, how the balance between the state of the art, the cost of implementation and the risk comes out, and whether a particular default meets the requirements of paragraph 2 are questions that require a legal examination of the individual case. CIVAC is not a law firm and does not provide legal advice. This article reproduces the wording of the Regulation and places it in context; the assessment of your case belongs with your data protection officer or with someone authorised to give it.

Frequently asked questions

Is it enough to check data protection by design once before a system goes live?

No. Art. 25(1) GDPR requires the measures “both at the time of the determination of the means for processing and at the time of the processing itself”. The check before go-live covers the first moment. The second lasts as long as processing takes place.

Does the duty under Art. 25 GDPR fall on the software manufacturer?

The wording of Art. 25(1) names the controller. A manufacturer that is not itself the controller of the processing is not the addressee of this provision. Recital 78 GDPR says that producers should be “encouraged” to take into account the right to data protection when developing their products. That does not shift a duty of the controller onto the manufacturer.

Does a certification under Art. 42 GDPR replace the demonstration under Art. 25?

No. Art. 25(3) GDPR allows an approved certification mechanism to be used “as an element” to demonstrate compliance, and Art. 42(4) makes clear that a certification does not reduce the controller's responsibility. It is one building block of the demonstration, with a term of at most three years under Art. 42(7).

What are the four dimensions of data protection by default?

Art. 25(2) sentence 2 GDPR names “the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility”. For each of these dimensions the default must be limited to what is necessary for the specific purpose of the processing.

When must the data protection officer be involved in design decisions?

Art. 38(1) GDPR requires that the data protection officer “is involved, properly and in a timely manner, in all issues which relate to the protection of personal data”. Applied to Art. 25 that means: before the means are determined, not after procurement.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles