GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.25: Data protection by design and by default

Both at the time the means of processing are determined and at the time of the processing itself, implement appropriate technical and organisational measures such as pseudonymisation which are designed to implement the data protection principles, in particular data minimisation, in an effective manner and to integrate the necessary safeguards into the processing, taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Separately, implement measures ensuring that by default only the personal data necessary for each specific purpose is processed, covering the amount of data collected, the extent of the processing, the period of storage and the accessibility of the data, and in particular ensuring that personal data is not by default made accessible to an indefinite number of natural persons without the individual's intervention.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 281 controls across 121 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 5 controls

  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 8.10 Information deletion
  • 8.11 Data masking
  • 8.3 Information access restriction
  • 8.33 Test information

ISO 27002:2022 · 5 controls

  • 5.34 Privacy and protection of PII
  • 8.10 Information deletion
  • 8.11 Data masking
  • 8.3 Information access restriction
  • 8.33 Test information

NIST SP 800-53 Rev 5 · 5 controls

  • NIST800-PL-8 Security and privacy architectures
  • NIST800-PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; Limit or
  • NIST800-SA-17 Developer Security and Privacy Architecture and Design. Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: Is consistent with the organization's
  • NIST800-SA-8 Security and privacy engineering principles
  • NIST800-SI-19 De-identification. Remove the following elements of personally identifiable information from datasets: [organization-defined] ; and Evaluate [organization-defined] for effectiveness of de-identification
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

C5 (Germany) · 4 controls

  • C5-DEV-10 Separation of environments
  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept
  • C5-OPS-24 Separation of Datasets in the Cloud Infrastructure
  • C5-PSS-08 Roles and Rights Concept

FedRAMP High · 4 controls

  • AC-6 Least Privilege
  • PL-8 Security and Privacy Architectures
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles

FedRAMP Moderate · 4 controls

  • AC-6 Least Privilege
  • PL-8 Security and Privacy Architectures
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles

ISO 27701:2019 · 4 controls

  • 6.11.2 Security in development and support processes
  • 7.4.1 Limit collection
  • 7.4.2 Limit processing
  • 7.4.4 PII minimization objectives
  • AC-6 Least Privilege
  • PL-8 Security and Privacy Architectures
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles
  • AC-6 Least Privilege
  • PL-8 Security and Privacy Architectures
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

Bahrain PDPL · 3 controls

ISO 13485 · 3 controls

ISO 27017 · 3 controls

ISO 27018 · 3 controls

ISO 27799 · 3 controls

ISO/IEC 27011:2024 · 3 controls

  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 3 controls

  • UGA-3 Accountability Principle
  • UGA-6 Personal Data Protection Office
  • UGA-7 Data Protection Officer
  • AUCDR-IS-3 Securely manage information assets over their lifecycle
  • AUCDR-PS-2 Privacy Safeguard 2 - Anonymity and pseudonymity
  • APP-11 APP 11 - Security of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing

ISO/IEC 27400:2022 · 2 controls

MARS-E · 2 controls

MDS2 (Medical Device) · 2 controls

MTCS (Singapore) · 2 controls

Mauritius DPA · 2 controls

Mexico LFPDPPP · 2 controls

  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

NIST SP 800-144 · 2 controls

  • NISTSP144-3 Data Classification, Handling, and Sovereignty
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 2 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Singapore · 2 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-4 Children's Data, DPIA, and Privacy by Design

PDPA Thailand · 2 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training

POPIA · 2 controls

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-7 Information Officer, Records of Processing, Notification, Training
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training

Privacy Act 2020 · 2 controls

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

Saudi Arabia PDPL · 2 controls

Uruguay DPL · 2 controls

APPI · 1 control

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • ASD37-27 Outbound data loss prevention (Very Good)

CCPA/CPRA · 1 control

  • §1798.121 Right to Limit Use and Disclosure of Sensitive Personal Information

DORA · 1 control

EU AI Act · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

IEEE 7000 · 1 control

ISMAP (Japan) · 1 control

ISO 26000:2010 · 1 control

ISO/IEC 23894:2023 · 1 control

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • PARAGUAY-5 Security of Processing, Data Integrity, Information Security

Peru DPL · 1 control

  • PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training

SOC 2 · 1 control

  • SOC2-P3.1 Personal information is collected consistent with privacy commitments

South Korea PIPA · 1 control

  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TISAXASS-3 Prototype Protection and Confidentiality

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

  • UKAI-2 Sector-Specific Regulator Engagement
  • UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.25 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 40 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 281 it maps to, and the evidence behind each claim, over MCP and REST.