Section 57: Data protection by design and default

Data Protection Act 2018 · 2018 c. 12View on legislation.gov.uk

Part 3: Law enforcement processing — CHAPTER 4: Controller and processor

Each controller must implement appropriate technical and organisational measures which are designed—

to implement the data protection principles in an effective manner, and
to integrate into the processing itself the safeguards necessary for that purpose.

The duty under subsection (1) applies both at the time of the determination of the means of processing the data and at the time of the processing itself.

Each controller must implement appropriate technical and organisational measures for ensuring that, by default, only personal data which is necessary for each specific purpose of the processing is processed.

The duty under subsection (3) applies to—

the amount of personal data collected,
the extent of its processing,
the period of its storage, and
its accessibility.

In particular, the measures implemented to comply with the duty under subsection (3) must ensure that, by default, personal data is not made accessible to an indefinite number of people without an individual's intervention.

About this text

This legislation text comes from legislation.gov.uk. Contains public sector information licensed under the Open Government Licence v3.0. These source and reuse terms cover the legislation text, not Remedy's commentary.

Reuse reviewed 21 August 2026 under Open Government Licence v3.0.