UK GDPR (UK General Data Protection Regulation)
Chapter IV: Controller and processor – UK GDPR (UK General Data Protection Regulation)

UK GDPR (UK General Data Protection Regulation) Art.25: Article 25 Data protection by design and by default

When determining the means of processing and during processing, the controller must implement appropriate measures, such as pseudonymisation, designed to implement the principles effectively and build in safeguards, taking into account the state of the art, cost, the nature and purposes and the risks. For information society services likely to be accessed by children the controller must take account of the children's higher protection matters: how children can best be protected and supported when using the service, that they merit specific protection because they may be less aware of risks and rights, and that they have different needs at different ages and stages of development. By default only the data necessary for each purpose may be processed, in amount, extent, storage period and accessibility, and data must not by default be made accessible to an indefinite number of people.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Chapter IV: Controller and processor – UK GDPR (UK General Data Protection Regulation)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.