Privacy by Design is a foundational principle under GDPR Article 25 requiring organizations to embed data protection into systems and processes from the outset, not as a compliance afterthought. The concept was developed by Ann Cavoukian and adopted into EU law as a binding GDPR obligation. Article 25 has two connected requirements: Privacy by Design (data protection built into systems before launch) and Privacy by Default (systems must apply the most privacy-protective settings by default — collecting minimum data, for the shortest necessary period). A consent management platform that blocks tracking scripts before consent is given directly implements Privacy by Default.