Basics 3 minutes read

Privacy as a design decision, not a retrofit

Article 25 GDPR requires two things that are easy to state and hard to retrofit: data protection by design and by default. Both are decided before the first line of code exists.

The two terms sit in the same article and are regularly confused. The difference is simple: the first concerns how something is built. The second concerns the settings it ships with.

Two requirements, one article

By design
By default
Question: how is it built?
Question: how does it come out of the box?
A form asks only for what is needed
The newsletter box is empty, not ticked
Logs store a hash instead of the IP address
A new account is not publicly visible at first
The retention period is part of the data model, not a later clean-up task
Visibility to search engines is off until someone turns it on

Why the timing decides everything

A decision that costs nothing at the start of a project costs a great deal later. A data field never collected needs no legal basis, no retention period, no entry in the register, no line in the privacy notice and no answer in an access request. A field to be removed only after two years drags all of that behind it – and additionally sits in backups, exports and reports.

That is the whole idea behind Article 25: the most effective data protection is the kind that requires nothing to be done, because the data never came into being.

Four questions before every new data field

  • Is this field genuinely needed?The most common reason for a field is that it was already in the template.
  • Would a coarser value do?Year of birth instead of date, postcode area instead of address, age bracket instead of age.
  • When may it go?The answer belongs in the same work package as creating it – otherwise it never comes.
  • Who gets to see it?Inside the organisation as well as outside it. Both belong in the answer.
The questions take a few minutes and can spare years of administration. Their answers are at the same time the raw material for the record of processing and for the privacy notice – both then arise in passing rather than later in one lump.

The arc back to the consent banner

That closes the circle back to the questions this series began with. A banner with every toggle set to "off" is privacy by default. Audience measurement that works without recognition is privacy by design – and makes the banner unnecessary for that purpose.

The most uncomfortable conclusion is also the most useful: most consent problems are not legal problems but consequences of a design decision taken earlier. Change that decision and the argument about banner design need never be had.

Data never collected needs no protecting, no deleting, no reporting and no explaining.

Published 5 October 2026

This article explains general principles and does not replace legal advice on an individual case.

Back to the overview