Abstract
Regulation 2016/679 regulated the principles of data protection by design and data protection by default. Those principles had been earlier shaped in the positions of the regulators. As a matter of fact, the duty to protect data by design is the requirement to implement adequate technical and organizational measures at the time when data processing methods are specified, that is before data is collected. Nevertheless, data protection by design and data protection by default include also a whole set of other provisions aimed at ensuring preventive and proactive data protection.