GDPR GDPR-Art.25: Data protection by design and by default
Both at the time the means of processing are determined and at the time of the processing itself, implement appropriate technical and organisational measures such as pseudonymisation which are designed to implement the data protection principles, in particular data minimisation, in an effective manner and to integrate the necessary safeguards into the processing, taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Separately, implement measures ensuring that by default only the personal data necessary for each specific purpose is processed, covering the amount of data collected, the extent of the processing, the period of storage and the accessibility of the data, and in particular ensuring that personal data is not by default made accessible to an indefinite number of natural persons without the individual's intervention.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 281 controls across 121 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; Limit or
NIST800-SA-17 Developer Security and Privacy Architecture and Design. Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: Is consistent with the organization's
NIST800-SA-8 Security and privacy engineering principles
NIST800-SI-19 De-identification. Remove the following elements of personally identifiable information from datasets: [organization-defined] ; and Evaluate [organization-defined] for effectiveness of de-identification
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
You are reading one control. How much of GDPR have you already done?
GDPR GDPR-Art.25 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 40 GDPR controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.