Default Settings
Default settings are the preset configurations, values, or behaviors that a system, software, or device uses automatically when a user has not made a specific choice. They represent the standard state a product ships with before anyone customizes it. In a privacy context, the way defaults are configured can significantly affect how much personal data is collected or shared, since many users never change them.
In information technology, a default is a pre-designed value or setting applied by software, a device, or a system when a specific value or setting has not been explicitly specified by the user. Default settings constitute the standard baseline configuration present at initial installation or provisioning and persist until deliberately overridden; systems can typically be reset to restore these original values. Note: the evidence packet describes 'default' as a general technical concept only and does not address privacy-by-default obligations or any GDPR provision, which should be evaluated separately against the current official text and applicable guidance.
Why it matters
Default settings carry outsized privacy significance because behavioral research and practical experience consistently show that most users never change the configuration a product ships with. When a system's defaults are set toward more data collection or wider sharing, that preset state effectively becomes the operative choice for the majority of a user base, regardless of what individuals might have selected if prompted. This is why the configuration of defaults is often treated as a design decision with direct consequences for how much personal data flows through a product.
The evidence digest describes 'default' purely as a general technical concept, so this entry does not itself establish any legal obligation. That said, readers should note that EU and UK data protection law contain a separate, distinct concept of data protection by default, which is addressed under its own provision and guidance and must be evaluated against the current official text. The technical notion of a default setting and the legal principle of privacy by default are related but not identical, and this definition should not be read as a statement of either the EU or UK obligation.
Because the boundary between a mere technical preset and a legally relevant default configuration depends on context, purpose, and applicable law, organizations should treat default configuration as a matter requiring separate assessment. What a product ships with can materially affect a later analysis of lawfulness, data minimization, and user expectations, so the initial state is generally worth documenting rather than assuming it is neutral.
Who it's relevant to
Inside Default Settings
Common questions
Answers to the questions practitioners most commonly ask about Default Settings.