GDPR · Regulation (EU) 2016/679
Article 25
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 6 parts · 4 Council drafts · 3 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in May Presidency compromise Council text
Comparison basis: Existing law (4 May 2016) compared with May Presidency compromise (21 May 2026)
Article 25
Data protection by design and by default
- 1.
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation,
in an effective manner andto integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. - 2.
The controller and the processor shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
- 3.
An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.
Article 25(1)
May Presidency compromise
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
Article 25(2)
May Presidency compromise
The controller and the processor shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
Article in June Presidency compromise · 10 June Council text
Comparison basis: Existing law (4 May 2016) compared with June Presidency compromise · 10 June (10 June 2026)
Article 25
Data protection by design and by default
- 1.
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation,
in an effective mannerand to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. - 2.
The controller and the processor shall implement appropriate technical and organisational measures
fortoensuringensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessiblewithout the individual's interventionto an indefinite number of natural persons without the individual's intervention. - 3.
An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.
Article 25(1)
June Presidency compromise · 10 June
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
Article 25(2)
June Presidency compromise · 10 June
2. The controller and the processor shall implement appropriate technical and organisational measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible to an indefinite number of natural persons without the individual's intervention.
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (4 May 2016) compared with June Presidency compromise · 18 June (18 June 2026)
Article 25
Data protection by design and by default
- 1.
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation,
in an effective mannerand to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. - 2.
The controller and the processor shall implement appropriate technical and organisational measures
fortoensuringensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessiblewithout the individual's interventionto an indefinite number of natural persons without the individual's intervention. - 3.
An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.
Article 25(1)
June Presidency compromise · 18 June
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
Article 25(2)
June Presidency compromise · 18 June
2. The controller and the processor shall implement appropriate technical and organisational measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible to an indefinite number of natural persons without the individual's intervention.
Article in September Presidency compromise Council text
Comparison basis: Existing law (4 May 2016) compared with September Presidency compromise (3 September 2026)
Article 25
Data protection by design and by default
- 1.
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation,
in an effective mannerand to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. - 2.
The controller and the processor shall implement appropriate technical and organisational measures
fortoensuringensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessiblewithout the individual's interventionto an indefinite number of natural persons without the individual's intervention. - 3.
An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.
Article 25(1)-(2)
September Presidency compromise
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
(7a) In Article 25, paragraphs 1 and 2 are replaced by the following: '1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. 2.The controller and the processor shall implement appropriate technical and organisational measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible to an indefinite number of natural persons without the individual's intervention.
Article 25(1) 3 Council drafts
Article 25(1)
21 May 2026 · May Presidency compromise
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
Article 25(1)
10 June 2026 · June Presidency compromise · 10 June
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
Article 25(1)
18 June 2026 · June Presidency compromise · 18 June
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
Article 25(1)-(2) 1 Council draft
Article 25(1)-(2)
3 September 2026 · September Presidency compromise
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
(7a) In Article 25, paragraphs 1 and 2 are replaced by the following: '1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, with particular regard to the lists referred to in Article 35(4) and (5), the controller and the processor shall, both at the time of the determination of the means for processing and at the time of the processing itself as applicable, implement, in an effective manner, appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. 2.The controller and the processor shall implement appropriate technical and organisational measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible to an indefinite number of natural persons without the individual's intervention.
Article 25(2) 3 Council drafts
Article 25(2)
21 May 2026 · May Presidency compromise
The controller and the processor shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
Article 25(2)
10 June 2026 · June Presidency compromise · 10 June
2. The controller and the processor shall implement appropriate technical and organisational measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible to an indefinite number of natural persons without the individual's intervention.
Article 25(2)
18 June 2026 · June Presidency compromise · 18 June
2. The controller and the processor shall implement appropriate technical and organisational measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible to an indefinite number of natural persons without the individual's intervention.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 1160 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler ITRE · LIBE
In Article 25, paragraph 1 and 2 are replaced by the following:
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. In doing so, particular attention shall be paid to the protection of the rights of children.
The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons. The default settings shall take into account, in particular, the vulnerability of children.
against:
Article 25
Data protection by design and by default
- 1.
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. In doing so, particular attention shall be paid to the protection of the rights of children.
- 2.
The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons. The default settings shall take into account, in particular, the vulnerability of children.
- 3.
An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.
Additional proposed wording Amendment 1170 · Axel Voss ITRE · LIBE
In Article 25, the following paragraphs are added:
Where personal data processing under paragraph 2 is carried out exclusively by means of Privacy-Enhancing Technologies certified pursuant to paragraph 4, the data controller shall benefit from a rebuttable presumption of compliance with the data minimisation principle under Article 5(1)(c) of Regulation (EU) 2016/679 in respect of that processing. All other obligations under Regulation (EU) 2016/679 shall continue to apply.
The Commission shall be empowered to adopt delegated acts recognising Privacy-Enhancing Technologies (PETs) and establishing the technical standards and criteria for Privacy-Enhancing Technologies eligible for certification under paragraph 3, following the governance model established in Article 41a of Regulation (EU) 2016/679. Those delegated acts shall be adopted in accordance with the examination procedure and following consultation with relevant authorities as appropriate. Standards shall include benchmarks to prevent misuse of PET certification for data practices that do not genuinely meet minimum privacy thresholds.
Justification
Certified PETs make data protection by design operational. Technologies such as differential privacy, homomorphic encryption, synthetic data and robust pseudonymisation reduce identifiability and support data minimisation while enabling data-driven innovation and AI. A rebuttable presumption under Article 5(1)(c) creates a real incentive to deploy certified PETs without exempting controllers from other GDPR duties. Commission-set, technology-neutral standards and benchmarks prevent PET-washing and support interoperable European privacy infrastructure.
against:
Article 25
Data protection by design and by default
- 1.
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
- 2.
The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
- 3.
An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.
- 3a.
Where personal data processing under paragraph 2 is carried out exclusively by means of Privacy-Enhancing Technologies certified pursuant to paragraph 4, the data controller shall benefit from a rebuttable presumption of compliance with the data minimisation principle under Article 5(1)(c) of Regulation (EU) 2016/679 in respect of that processing. All other obligations under Regulation (EU) 2016/679 shall continue to apply.
- 3b.
The Commission shall be empowered to adopt delegated acts recognising Privacy-Enhancing Technologies (PETs) and establishing the technical standards and criteria for Privacy-Enhancing Technologies eligible for certification under paragraph 3, following the governance model established in Article 41a of Regulation (EU) 2016/679. Those delegated acts shall be adopted in accordance with the examination procedure and following consultation with relevant authorities as appropriate. Standards shall include benchmarks to prevent misuse of PET certification for data practices that do not genuinely meet minimum privacy thresholds.
Additional proposed wording Amendment 1173 · Axel Voss ITRE · LIBE
7c. In Article 25, the following paragraph 2a is added:
In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters. The children’s higher protection matters are:
how children can best be protected and supported when using the services, and;
the fact that children:
merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing; and
have different needs at different ages and at different stages of development.
This paragraph is not to be read as implying anything about the matters that may be relevant to the assessment of what are appropriate technical and organisational measures for the purposes of paragraph 1 and 2 in cases other than those described in this paragraph. In this paragraph “information society services” does not include preventive or counselling services."
Justification
The amendment makes children’s higher protection needs a concrete part of data protection by design for information society services likely to be accessed by children. Controllers must consider how children can best be protected and supported, including their lower awareness of risks and their different needs at different ages and development stages. This creates clearer duties without a one-size-fits-all model, preserves other Article 25 assessments and excludes preventive or counselling services.
against:
Article 25
Data protection by design and by default
- 1.
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
- 2.
The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
- 2a.
In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters. The children’s higher protection matters are:
- (a)
how children can best be protected and supported when using the services, and;
- (b)
the fact that children:
- (i)
merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing; and
- (ii)
have different needs at different ages and at different stages of development.
- (i)
-
This paragraph is not to be read as implying anything about the matters that may be relevant to the assessment of what are appropriate technical and organisational measures for the purposes of paragraph 1 and 2 in cases other than those described in this paragraph. In this paragraph “information society services” does not include preventive or counselling services."
- (a)
- 3.
An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 25(1)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 25(1)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 25(2)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 25(2)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded