Files
llm-wiki/raw/official-docs/privacy-gdpr-article-25-design.md
T

9.8 KiB

title, source_type, status, confidence, url, archive_url, tags, related_branches, related_projects, created, last_reviewed
title source_type status confidence url archive_url tags related_branches related_projects created last_reviewed
GDPR Article 25 — Data protection by design and by default official-doc raw high https://gdpr-info.eu/art-25-gdpr/ https://web.archive.org/web/2024/https://gdpr-info.eu/art-25-gdpr/
privacy
gdpr
data-retention
privacy-by-design
ca-skeleton
feature-data-retention-privacy-contract
ca-skeleton-operational-contract
2026-05-22 2026-05-27

GDPR Article 25 — Data protection by design and by default

Layer: raw/official-docs/ — Regulation (EU) 2016/679 Article 25 (privacy by design + by default) 의 verbatim 발췌. ca-tmpl retention/redaction/pseudonymization 결정의 legal basis 1차 근거.

Parent / 활용 branch (필수)

Branch 이 자료가 정당화하는 결정
raw/branch-notes/feature-data-retention-privacy-contract ca-tmpl 의 application log 30d / security 180d / audit 365d retention 과 HMAC-SHA-256 + 90d salt rotation pseudonymization 의 legal basis (Art. 25(1) pseudonymisation + Art. 25(2) storage limitation)
raw/project-notes/ca-skeleton-operational-contract ca-tmpl baseline 의 "GDPR aligned" 외부 산출물 표현 근거

컨텍스트

ca-tmpl 의 retention/redaction/pseudonymization 결정(feature-data-retention-privacy-contract) 이 단순히 "30/180/365일" 이라는 수치 뿐 아니라 legal basis 가 있어야 외부 산출물에서 "GDPR aligned" 라고 말할 수 있음. Article 25 는 storage limitation, data minimization, pseudonymization 을 default 로 요구하는 핵심 조항.

출처 / Source

핵심 인용 / Key quotes (verbatim)

Article 25(1) — Data protection by design

[§Art. 25(1)] "Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects."

Article 25(2) — Data protection by default

[§Art. 25(2)] "The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed."

[§Art. 25(2)] "That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility."

[§Art. 25(2)] "In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons."

EDPB Guidelines 4/2019 (보조)

EDPB Guidelines 4/2019: "Retention periods should be set as short as possible and reviewed regularly. Pseudonymisation, encryption and access controls are among the key safeguards."

Claims Extracted / 추출된 주장

Claim ID Claim (이 자료가 직접 말하는 것) Evidence quote Strength Applies to Does not prove
GDPR-A25-C1 Art. 25(1) 는 controller 가 처리 수단 결정 시점 + 처리 자체 시점 양쪽에서 pseudonymisation 과 같은 적절한 기술·조직 조치 를 구현하여 data-protection 원칙(data minimisation 등)을 effective 하게 실현할 의무를 진다 — state of the art / cost / nature·scope·context·purposes / risk 를 고려한 비례성 적용 [§Art. 25(1)] "the controller shall ... implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner" official-standard EU controllers / EU residents 의 personal data 를 처리하는 모든 시스템 "pseudonymisation 이 항상 필수" 의 뜻은 아님 — "such as pseudonymisation" 은 예시. 비례성/risk 평가에 따라 다른 조치 가능
GDPR-A25-C2 Art. 25(2) 는 controller 가 by default 로 각 처리 목적에 필요한 personal data 만 처리되도록 보장하는 기술·조직 조치를 구현해야 한다 [§Art. 25(2)] "the controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed." official-standard 모든 EU 적용 controller 특정 retention 일수 / 저장 기간 / pseudonymization 알고리즘이 강제된다는 뜻은 아님 — "necessary for purpose" 의 정량 기준은 도메인별
GDPR-A25-C3 Art. 25(2) 의 default 의무는 (i) 수집되는 personal data 의 양, (ii) 처리 범위, (iii) 저장 기간, (iv) 접근성 4가지 모두에 적용된다 [§Art. 25(2)] "That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility." official-standard 시스템 설계 시 4축 모두 고려 의무 4가지 외의 차원 (예: 위치, 처리 빈도) 은 본 조항이 직접 다루지 않음 — 다른 GDPR 조항으로 보강
GDPR-A25-C4 Art. 25(2) 는 특히 personal data 가 개인의 개입 없이 (without the individual's intervention) 무제한의 자연인에게 접근 가능하도록 만들어서는 안 된다고 명시 — 예: 기본 공개 설정 금지 [§Art. 25(2)] "In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons." official-standard social/sharing 기능 / 기본 공개 설정 의 default 정책 공개 설정 자체가 금지된다는 뜻은 아님 — "by default" + "without individual's intervention" 조합이 핵심

Usage Boundaries / 적용 경계

  • 이 자료가 직접 증명하는 것:
    • GDPR-A25-C1: pseudonymisation 이 Art. 25(1) 의 명시적 예시로 등장. ca-tmpl 의 HMAC-SHA-256 + 90d salt rotation 이 "appropriate technical measure" 후보임
    • GDPR-A25-C2: data minimisation 의 default 의무
    • GDPR-A25-C3: 저장 기간 (retention) 이 default 의무의 4축 중 하나로 명시 — ca-tmpl 30/180/365d 의 legal basis
    • GDPR-A25-C4: 기본 공개 설정 금지 원칙
  • 이 자료가 증명하지 않는 것:
    • 30/180/365일 retention 이 GDPR 이 요구하는 정확한 수치 — Art. 25 는 수치를 지정하지 않음. "as short as possible" 원칙만 (EDPB 가이드 보조)
    • HMAC-SHA-256 + 90d salt rotation 이 pseudonymisation 의 충분조건 — 알고리즘 강도/key management 는 ENISA / IAPP 가이드 보강 필요
    • ca-tmpl 의 DSR delete SLA 30일이 Art. 25 의 직접 요구 — 별도 Art. 12(3) "without undue delay and in any event within one month" 와 결합 해석 필요
    • 4축 (수집량/처리범위/저장기간/접근성) 외 차원에 대한 default 의무
  • 내 프로젝트에 적용하려면 추가 확인이 필요한 것:
    • ca-tmpl 의 "necessary for purpose" justification 을 도메인별 (application / security / audit log) 로 명문화
    • is_sample column 이 data minimization 원칙과 호환됨을 운영 정책 문서로 명문화
    • 90d salt rotation 이 EDPB 가 권장하는 "periodic re-pseudonymisation" 의 적정 주기인지 별도 검토

메모

  • ca-tmpl 과의 매핑 (자료 직접 인용 아님):
    • application log 30일 / security 180일 / audit 365일 retention 은 Art. 25(2) "period of their storage" 원칙과 호환. 단, "necessary for each specific purpose" justification 이 도메인별로 따로 필요.
    • HMAC-SHA-256 salt rotation 90d 는 Art. 25(1) "pseudonymisation" 의 기술적 조치에 해당. salt rotation 이 없으면 pseudonymization 이 사실상 정적 hash 가 되어 re-identification risk 증가.
    • is_sample column 은 data minimization 원칙과 충돌하지 않음 (prod 에서 sample 이 절대 seed 되지 않음을 보장).
  • 한계: Article 25 자체는 retention 수치를 지정하지 않음. "as short as possible" 원칙만. 30/180/365일은 ca-tmpl 의 운영적 기본값 일 뿐 법적 강제값 아님.
  • ca-tmpl 의 DSR SLA(delete 30d / export 14d) 는 Article 12(3) "without undue delay and in any event within one month" 와 호환.