GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.25: Data protection by design and by default

Both at the time the means of processing are determined and at the time of the processing itself, implement appropriate technical and organisational measures such as pseudonymisation which are designed to implement the data protection principles, in particular data minimisation, in an effective manner and to integrate the necessary safeguards into the processing, taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Separately, implement measures ensuring that by default only the personal data necessary for each specific purpose is processed, covering the amount of data collected, the extent of the processing, the period of storage and the accessibility of the data, and in particular ensuring that personal data is not by default made accessible to an indefinite number of natural persons without the individual's intervention.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 276 controls across 119 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 3.2.1 3.2.1 Data protection by design and default in monitoring devices and tools
  • 5.3(a) 5.3(a) Network and TLS inspection tuned to prevent permanent logging of employee activity
  • 5.3(b) 5.3(b) Exclude sensitive traffic from inspection and tell employees what is monitored
  • 5.3(f) 5.3(f) Data loss prevention: transparent rules and a warning before an email is blocked
  • 5.3(g) 5.3(g) Private spaces in employer-provided online applications
  • 5.4.2(a) 5.4.2(a) Bring your own device: separate private from business use and keep out of private areas
  • 3.1.2(b) 3.1.2(b) Necessity in place and time: when cameras run, and no filming beyond the property boundary
  • 5.2(a) 5.2(a) Biometric templates: no excess data and no transfer across systems
  • 5.2(b) 5.2(b) Biometric templates: stored on the user's own device, or encrypted centrally with a key only the person holds
  • 9.2 9.2 Data protection by design and by default in the system and in the purchase specification
  • 9.3 9.3 Privacy-friendly technology on; unnecessary functions (zoom, pan, audio, analytics) off

ISO 27001:2022 · 5 controls

  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 8.10 Information deletion
  • 8.11 Data masking
  • 8.3 Information access restriction
  • 8.33 Test information

ISO 27002:2022 · 5 controls

  • 5.34 Privacy and protection of PII
  • 8.10 Information deletion
  • 8.11 Data masking
  • 8.3 Information access restriction
  • 8.33 Test information

NIST SP 800-53 Rev 5 · 5 controls

  • NIST800-PL-8 PL-8 Security and Privacy Architectures
  • NIST800-PM-25 PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research
  • NIST800-SA-17 SA-17 Developer Security and Privacy Architecture and Design
  • NIST800-SA-8 SA-8 Security and Privacy Engineering Principles
  • NIST800-SI-19 SI-19 De-identification
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

C5 (Germany) · 4 controls

  • C5-DEV-10 Separation of environments
  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept
  • C5-OPS-24 Separation of Datasets in the Cloud Infrastructure
  • C5-PSS-08 Roles and Rights Concept

FedRAMP High · 4 controls

  • AC-6 Least Privilege
  • PL-8 Security and Privacy Architectures
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles

FedRAMP Moderate · 4 controls

  • AC-6 Least Privilege
  • PL-8 Security and Privacy Architectures
  • SA-3 System Development Life Cycle
  • SA-8 Security and Privacy Engineering Principles

ISO 27701:2019 · 4 controls

  • 6.11.2 Security in development and support processes
  • 7.4.1 Limit collection
  • 7.4.2 Limit processing
  • 7.4.4 PII minimization objectives
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

Bahrain PDPL · 3 controls

ISO 27799:2025 · 3 controls

  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 3 controls

  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-4 Security, Accuracy
  • TRINIDAD-5 Enforcement and Sanctions
  • UGA-3 Accountability Principle
  • UGA-6 Personal Data Protection Office
  • UGA-7 Data Protection Officer
  • AUCDR-IS-3 Securely manage information assets over their lifecycle
  • AUCDR-PS-2 Privacy Safeguard 2 - Anonymity and pseudonymity
  • APP-11 APP 11 - Security of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • ACT-2 ACT-2 Show the device is necessary: no less intrusive means, only the data, retention and access strictly required
  • TLW-2 TLW-2 Do not impose cameras on in videoconferences unless background blur is available or the meeting requires it
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

ISO/IEC 27400:2022 · 2 controls

  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion
  • JO-PDPL-Personal-Data-Protection-Council-Article4-5-6-Establishment-MoDEE-Functions-Powers-Investigation Jordan PDPL Personal Data Protection Council + Articles 4-5-6 + Establishment + Ministry of Digital Economy and Entrepreneurship (MoDEE) + Functions + Powers + Investigation + Administrative Penalties + Council Composition + International Cooperation
  • JO-PDPL-Training-Awareness-Penalties-Article22-23-24-Compensation-Administrative-Criminal-100K-200K-JOD Jordan PDPL Training + Awareness + Penalties + Articles 22-23-24 + Compensation + Administrative Penalties JOD 100K + JOD 200K Repeat + Criminal 3 Years + Civil Compensation + Director Liability + Reasonable Care Defence

MARS-E · 2 controls

MDS2 (Medical Device) · 2 controls

  • MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring
  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS

MTCS (Singapore) · 2 controls

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA
  • MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS

Mauritius DPA · 2 controls

  • MU-DPA-Cross-Border-Transfer-Section-36-Adequacy-SCC-BCR-Mauritius-Global-Business-IBC-Financial-Services Mauritius DPA Cross-Border + Section 36 + Adequacy + SCC + BCR + Mauritius Global Business + Financial Services
  • MU-DPA-Security-Breach-Notification-Section-25-BREACH-72-Hour-Commissioner-Cyber-Security-Strategy Mauritius DPA Security + Breach Notification + Section 25-BREACH + 72 Hour + Commissioner + Cyber Security Strategy

Mexico LFPDPPP · 2 controls

  • MX-LFPDPPP-Cross-Border-Transfer-Articles-36-37-Reglamento-66-68-Domestic-International-APEC-CBPR-USMCA Mexico LFPDPPP Cross-Border + Articles 36-37 + Reglamento 66 + 68 + Domestic + International + APEC CBPR + USMCA
  • MX-LFPDPPP-Security-Breach-Notification-Reglamento-63-No-Time-Limit-INAI-Recommendations-CERT-MX Mexico LFPDPPP Security + Breach Notification + Reglamento 63 + No Specified Time + INAI Recommendations + CERT-MX
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

NIST SP 800-144 · 2 controls

  • NISTSP144-3 Data Classification, Handling, and Sovereignty
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 2 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Singapore · 2 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-4 Children's Data, DPIA, and Privacy by Design

PDPA Thailand · 2 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training

POPIA · 2 controls

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-7 Information Officer, Records of Processing, Notification, Training
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training

Privacy Act 2020 · 2 controls

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

Saudi Arabia PDPL · 2 controls

  • SA-PDPL-19 Data protection officer designation
  • SA-PDPL-21 Data protection impact assessments
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • SWE-1 Scope and Purpose
  • SWE-2 Relationship to GDPR
  • Standard 15 Online Tools
  • Standard 2 Data Protection Impact Assessments
  • UKGDPRREG-2 Data Subject Rights (Articles 12-22)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)

Uruguay DPL · 2 controls

  • URUGUAY-4 Security and Cross-Border
  • URUGUAY-5 Database Registration with AGESIC URCDP

APPI · 1 control

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • ASD37-27 Outbound data loss prevention (Very Good)
  • AL-DPA-14 Direct Marketing

CCPA/CPRA · 1 control

  • §1798.121 Right to Limit Use and Disclosure of Sensitive Personal Information
  • AUCDR-OB-3 Data minimisation

DORA · 1 control

EU AI Act · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • s71 s 71 Build in data protection by design and by default

IEEE 7000 · 1 control

  • IEEE7000-Operations-Lifecycle-OngoingMonitoring-Incident-Decommissioning IEEE 7000 - Operations + Lifecycle + Ongoing AI Risk Monitoring + Data Provenance + Retention + Privacy + Safe Deployment + Decommissioning + Disposal
  • 5.7 5.7 Regular review to minimize data and improve privacy

ISMAP (Japan) · 1 control

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI
  • INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

  • JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle

LGPD · 1 control

  • LGPD-BR-Governance-Encarregado-DPO-ROPA-DPIA-Privacy-by-Design-Article-46-50-Codes-of-Conduct Brazil LGPD Governance + Encarregado (DPO) + ROPA + DPIA + Articles 46-50

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-DPO-Designation-Class-Data-User-Registration-DPIA-Code-Practice-Section-43A-2024-Amendment Malaysia PDPA Governance + DPO Section 43A + Class of Data User Registration + DPIA + Code of Practice
  • MN-CDPA-Data-Privacy-Assessment-DPIA-Section-325O-07-Sensitive-Targeted-Sale-Profiling-AI-Consumer-Health Minnesota CDPA DPIA + Section 325O.07 + Sensitive + Targeted + Sale + Profiling + AI + Consumer Health
  • MT-CDPA-Data-Protection-Assessment-MCA-30-14-2815-Sensitive-Targeted-Sale-Profiling-AG-Inspection Montana CDPA Data Protection Assessment + MCA 30-14-2815 + Sensitive + Targeted + Sale + Profiling + AG Inspection

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • PARAGUAY-5 Security of Processing, Data Integrity, Information Security

Peru DPL · 1 control

  • PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training

SOC 2 · 1 control

  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC-CY-C2 Encryption and Data Protection

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TISAXASS-3 Prototype Protection and Confidentiality

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TSSR-INFO-1 Network Data Protection
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • UKAI-2 Sector-Specific Regulator Engagement
  • UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity
  • CPSC-CS.3 Data Protection for Safety Systems
  • US-ITAR-EAR-DS-01 Technical Data Protection

Vietnam PDPD · 1 control

  • VIETNAMPDP-3 Data Subject Rights

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.25 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 276 it maps to, and the evidence behind each claim, over MCP and REST.