Controllers must embed data-protection principles and safeguards into systems and processing and ensure default settings limit data, extent, retention and accessibility to what each purpose requires.
Interpretation and application must be checked against the official text and current version.
