Guidelines on Data Protection by Design & Default

22 ottobre 2020

On October, 21, 20202, the EDPB adopted a final version of the Guidelines on Data Protection by Design & Default. The guidelines focus on the obligation of Data Protection by Design and by Default (DPbDD) as set forth in Art. 25 GDPR. The core obligation enshrined in Art.25 is the effective implementation of the data protection principles and data subjects’ rights and freedoms by design and by default. This means that controllers have to implement appropriate technical and organisational measures and the necessary safeguards, designed to ascertain data protection principles in practice and to protect the rights and freedoms of data subjects. In addition, controllers should be able to demonstrate that the implemented measures are effective. 

The Guidelines also contain guidance on how to effectively implement the data protection principles in Article 5 GDR, listing key design and default elements, as well as practical cases for illustration. They further provide recommendations on how controllers, processors and producers can cooperate to achieve DPbDD.

Archivio news

 

News dello studio

ott8

08/10/2026

Gaming:action to protect gamers' rights

The Consumer Protection Cooperation (CPC) Network has launched EU-level coordinated actions in relation to nine video games companies, aiming to strengthen the protection of gamers' rights. With

ott8

08/10/2026

Gaming: avviate azioni coordinate, ai sensi del Regolamento (UE) n. 2394/2017, nel settore del gaming nei confronti di dieci società di videogiochi

Le autorità di tutela del consumatore europee, coordinate, dalla Commissione Ue, hanno avviato azioni coordinate nel settore nei confronti di società di videogiochi per promuovere trasparenza

ott7

07/10/2026

Cessione di ramo di azienda

A partire dal 1 gennaio 2027, trova applicazione l'art. 16 del16, D.Lgs. n. 173/2024, in vigore dal 29/11/2024. Il citato articolo dispone quanto segue: "1.    Il cessionario è responsabile