Data protection by design implies that, both at the time of determining the means of processing and at the time of the processing itself, you must apply appropriate technical and organisational measures designed to effectively apply the principles of data protection and integrate into the processing the guarantees necessary to comply with the requirements of the Regulation (for example, encryption, anonymisation, etc.).
Likewise, data protection by default means applying the appropriate technical and organisational measures to ensure that, by default, only the personal data necessary for each specific purpose of the processing are processed. This obligation applies to the amount of personal data collected, the scope of the processing, the retention period and the accessibility of the data.
Highlights