Organization should implement data protection by design and by default
Medium
Cross-cloud
General
manual-gdpr-privacy-by-design
How to fix it
Implement data protection by design and by default per Article 25. Consider data minimization, pseudonymization, and privacy-enhancing technologies at the design stage of systems and processes.
How to verify
- Verify privacy-by-design principles in development process
- Confirm data minimization reviews for new features
- Verify default privacy settings are restrictive
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Cross-cloud rules
- Block storage volumes must be encrypted
- Cache service security hardening
- Cache services must enforce TLS encryption in transit
- Container registry security hardening
- Database authentication must use managed identities
- Databases must not be publicly accessible
- IAM password policy must require minimum length of 14
- Key management service security hardening