By design, the controller must consider from the earliest stages of a project the risks that certain processing poses to data subjects' rights given the state of the art, nature and purposes, and implement technical, organisational and other measures to meet its obligations; by default, it must apply measures so that only the data necessary for each purpose are processed. The Reglamento requires design measures to be set before processing, having regard to nature, scope and purpose, risks of varying likelihood and severity, the state of the art and cost; default settings must limit the amount collected, the extent of processing, the storage period and accessibility, and must prevent data being accessible to an indefinite number of people automatically; certification may show compliance. The Superintendencia's guide on data protection by design and by default (21 October 2025) makes its principles (zero-trust data protection, with privacy, security and risk practices built into software development) binding where applicable to developing, customising or implementing software and information systems that process personal data.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.