Data Protection by Default
Data protection by default means that when a product or service is set up, the settings should automatically protect people's personal data without the user having to change anything. For example, features such as automatic opt-ins should not be switched on by default, and only the personal data actually needed should be processed. The goal is to give users the highest privacy protection as the starting point.
Data protection by default is an obligation under the EU General Data Protection Regulation requiring organisations to implement appropriate technical and organisational measures ensuring that, by default, only personal data necessary for each specific purpose of processing is processed. Regulatory guidance emphasises applying default settings that favour privacy, such as not enabling automatic opt-ins on customer account pages and putting safeguards in place to prevent personal data being made available to an indefinite number of people without the individual's intervention. It is a companion obligation to data protection by design and is widely regarded as one of the core accountability principles of the GDPR. The precise measures required are fact-specific and depend on the nature, scope, context, and purposes of the processing; this definition addresses the principle generally under EU (and UK GDPR) frameworks and does not resolve how it applies to any particular processing activity or non-EU regime.
Why it matters
Data protection by default shapes the baseline experience that every user encounters before they make any active choice. Because most people never change default settings, the configuration an organisation ships with often determines how much personal data is actually collected and shared. Under the GDPR, this is not merely good practice but a legal obligation: by default, only the personal data necessary for each specific purpose should be processed, and safeguards must be in place to prevent personal data being made available to an indefinite number of people without the individual's intervention. In the cookie consent context, this principle directly informs why practices such as automatic opt-ins, for example pre-enabled analytics or advertising cookies, or pre-ticked boxes on account pages, are widely regarded as problematic in EU and UK GDPR frameworks.
For teams designing consent interfaces, the principle raises the stakes on how banners, preference centres, and account settings are constructed. A cookie banner that treats non-essential cookies as enabled until a user opts out sits in tension with data protection by default, because the privacy-protective option is not the starting point. Regulatory guidance across EU authorities emphasises that default settings should favour privacy, meaning the burden should not fall on users to hunt for and disable data-hungry features.
It is important to recognise that data protection by default is a companion obligation to data protection by design and is regarded as one of the core accountability principles of the GDPR, but the precise measures required are fact-specific. This definition addresses the principle generally under EU and UK GDPR frameworks and does not resolve how it applies to any particular processing activity or to non-EU regimes, which may take different approaches, such as opt-out models under some US state privacy laws.
Who it's relevant to
Inside Data Protection by Default
Common questions
Answers to the questions practitioners most commonly ask about Data Protection by Default.