How to comply with new rules for privacy assessments, automated decisionmaking, & cybersecurity audits

Thank you!
Please check your email to view the guide.

The 7 GDPR principles: Article 5 data protection explained

April 11, 2023
5
 mins read
Last Updated date
August 13, 2026
Robert Bateman
Robert Bateman
Senior Partner at Privacy Partnership law firm
Detailed guide to Article 5 requirements across live data flows

The seven  GDPR principles have been in force since May 25, 2018, and govern how organizations collect, share, store, secure, and otherwise use personal data.  These principles are central to GDPR compliance because they shape almost every decision a privacy team makes about data processing.

Following the principles is a core part of GDPR compliance. The principles help you respect people’s privacy, avoid administrative fines, and develop your products in a safe and sustainable way.

This article will explain each of the seven General Data Protection Regulation (GDPR) principles and provide some practical examples of how to achieve compliance.

Privado AI identifies GDPR risks by scanning websites and mobile apps without any implementation

What are the GDPR principles, and why do they matter?

The General Data Protection Regulation (GDPR) is the European Union’s main law for protecting personal data. It gives people rights over how organizations collect, use, store, disclose, and protect their information. It also imposes enforceable duties on any organization within its scope.

That scope is wider than many US businesses expect. Here is a quick comparison of the GDPR Article 5 framework vs. US Privacy Laws:

Area

Article 5 framework

US privacy laws

Legal structure

Establishes principles that apply across covered personal data processing.

Federal sector rules and state laws impose different obligations based on data type, entity, and jurisdiction.

Consent and lawful basis

Processing needs a lawful basis. Consent must meet GDPR standards when used.

Opt-in and opt-out duties depend on the law, data type, and processing purpose.

Individual rights

Rights include access, correction, erasure, restriction, portability, and objection.

Available rights vary by state and may include access, correction, deletion, portability, and the right to opt out.

Accountability

Controllers must demonstrate compliance with the principles set out in Article 5.

Assessments, notices, contracts, and records depend on the applicable statute.

Where are the GDPR principles found?

The key principles are set in Article 5 of the General Data Protection Regulation. 

Article 5(1) lists the six substantive GDPR principles that govern processing behavior across every stage of the data lifecycle.

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality

Article 5(2) adds accountability as a separate obligation on the data controller. 

UK GDPR was built on the same seven-principle structure post-Brexit, though 2026 reforms have introduced some divergence from the EU framework. Organizations processing UK personal data still face a seven-principle framework enforced by the Information Commissioner’s Office (ICO).

UK GDPR retained the same seven-principle structure after Brexit. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, with most data protection provisions commencing 5 February 2026, and created the first material divergence from the EU framework. The seven principles are unchanged, but the UK now recognizes a seventh lawful basis under Article 6 - recognised legitimate interests - which has no EU equivalent. The Data Use and Access Act (DUAA) also replaces the Information Commissioner's Office with a new Information Commission.

Who must comply with the GDPR principles?

Article 3 applies the regulation to any organization with an EU establishment, and to organizations outside the EU that offer goods or services to people located in the EU or monitor their behavior there.

Three categories fall within scope. 

  1. Controllers established in the EU
  2. Controllers outside the EU that target EU residents with goods or services
  3. Processors handling personal data on behalf of an in-scope controller.

Public authorities, private companies, and non-profits are all covered. Size is not a defense. A US ecommerce company shipping to Berlin faces the same seven principles as a Frankfurt-based bank.

Organizations uncertain about their position should assess their processing activity and seek qualified legal guidance where necessary. A GDPR compliance checklist can help map obligations to specific processing activities inside the business.

What are the 7 GDPR principles?

Six of the seven GDPR principles govern what you do with personal data. The seventh governs whether you can prove it. They apply across the full lifecycle, from collection and use to sharing, retention, security, and deletion.

The sections below explain how each GDPR principle works, what it requires from organizations, and how privacy and product teams can apply it in practice.

Seven GDPR principles summarized for practical privacy programs

Lawfulness, fairness, and transparency

“Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.”

The first GDPR principle is really three principles in one—so let’s break it down into its three parts.

Lawfulness

Under the GDPR, you can’t process personal data unless you have a “legal basis” (or “lawful basis”). You must also ensure you comply with other relevant laws—for example, the ePrivacy Directive, which regulates cookies

(💡 “Processing” personal data means using it in basically any way, including collecting it, storing it, sharing it, or erasing it).

There are six legal bases listed at Article 6 of the GDPR. Before processing personal data, you must identify whether one of these legal bases applies.

  • Consent: A person has given you permission to process their personal data via a “freely given, specific, informed and unambiguous… clear affirmative action”.
  • Contract: You need to process personal data to either enter into a contract or perform your obligations under a contract (e.g., you need a person’s address to send them a product).
  • Legal obligation: The law requires that you process personal data (e.g., to keep legally mandated accounting records).
  • Vital interests: You need to process personal data to protect someone’s life or health (e.g., to provide personal details in a medical emergency).
  • Public task: You need to process personal data to complete a task in the public interest or under official authority (e.g., registering students at a university).
  • Legitimate interests: You need to process personal data to pursue a legitimate purpose that benefits you or a third party (e.g., fraud detection).

If you process “special category data”—such as information about a person’s health, political beliefs, or race—you also need an additional legal basis under Article 9 of the GDPR. You can read more about lawfulness criteria in GDPR

Fairness

According to the UK’s data regulator, the “fairness” element means that you must “stop and think not just about how you can use personal data, but also about whether you should. The outcome should not create unjustified or unexpected harm.

A fair processing review should address the following questions:

  • Could the processing create material harm or disadvantage?
  • Would people reasonably expect this use of their data?
  • Can the organization explain and justify any unexpected impact?
  • Does the design avoid deceptive choices or misleading statements?

Transparency

Transparency is a vital part of GDPR compliance. You must explain practically everything you do with personal data under the GDPR.

For example, you’ll need:

  • A privacy notice explaining how and why you use personal data, who you might share personal data with, and how people can exercise their data subject rights (among other things).
  • Shorter notices, provided whenever you collect personal data, explaining why you need it and what you’ll use it for (e.g. as part of a cookie banner or newsletter signup form).
For mobile products, transparency also extends to app store declarations. Privado AI’s mobile app privacy guidance explains how app owners can assess SDKs, consent flows, third-party data flows, and declared practices.

Other third parties, such as Google Play and Apple’s App Store, also require you to provide transparency information.

But to be transparent, you need to fully understand how your organization and products use personal data.

Example: You’re developing an Android app. You must provide Google Play with a “data safety report” explaining how you collect, share, and use personal data. You can use a code-scanning tool to be confident that you’re providing all the relevant information.

Purpose limitation

“Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.”

Under the “purpose limitation” principle, you should: 

  • Only collect data for a “specified, explicit, and legitimate” purpose, and
  • Not use the data for another, “incompatible” or unrelated purpose.

There are exceptions to these rules on “further processing”, e.g., for historical research purposes and statistical purposes.

Example: You’re developing an app. You collect a user’s phone number for security purposes (multi-factor authentication). You shouldn’t use the person’s phone number for marketing purposes without their consent.

Data minimization

“Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.”

The “data minimization” principle requires that you only process the personal data you need—no more, no less.

Data minimization is closely linked to the concept of “privacy by design”—embedding privacy and data protection into your projects from the earliest stages.

Example: You’re developing an app. You use privacy code scanning to discover how your product collects, uses, and stores personal data. You can now see whether you are collecting or using unnecessary personal data—and you can decide what to do about it.

Accuracy

“Personal data shall be accurate and, where necessary, kept up to date.”

Under the “accuracy” principle, you must: 

  • Ensure personal data is accurate and up to date.
  • Take “every reasonable step” to correct or update inaccurate or incomplete data.

As noted by the Digital Marketing Association (DMA), the accuracy principle extends to customer profiles generated for marketing purposes. The DMA suggests that embedding a privacy-by-design approach can help meet the accuracy requirement.

Inaccurate data causes real harm. In 2021, the Spanish regulator fined Equifax Ibérica €1 million over a debtor database assembled from public registers. Accuracy was one of four Article 5 principles breached, alongside lawfulness and transparency, purpose limitation, and data minimization — the AEPD said the size of the penalty reflected how many principles were involved. More than a quarter of complainants had already given Equifax documents showing the debts were settled or were never theirs.

Storage limitation

“Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.”

Under the “storage limitation” principle, you must not keep personal data for longer than you need it.

You should tell people how long you’ll keep each type of personal data you collect. You might store personal data for:

  • A specific time period (e.g., one year).
  • Until a trigger event prompts you to delete it (e.g., until a user deletes their account).

You should always have a good reason to keep personal data for any given period. Some types of processing can require you to store personal data for longer periods, e.g. for archiving purposes and scientific or historical research.

Integrity and confidentiality (security)

“Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures.”

The “integrity and confidentiality” principle is where data protection meets data security. You must take appropriate “technical measures” and “organizational measures” to secure people’s data, guard against internal and external threats, and prevent data breaches.

We can find more details on the GDPR’s security requirements at Article 32, which mentions that you should:

  • Encrypt and pseudonymize (remove identifiers from) personal data where appropriate.
  • Ensure the “confidentiality, integrity, availability, and resilience” of any system you use for processing personal data.
  • Make sure you can quickly restore access to personal data if you have a physical or technical issue.
  • Regularly test your security measures.

All members of your team should receive training on data security and GDPR compliance.

And if your company develops digital products, engineers have a crucial role in ensuring data security from the start of the development cycle, for example, by:

  • Identifying data leaks.
  • Identifying insecure data storage practices.
  • Preventing unnecessary or insecure data collection and data sharing.
  • Incorporating data security controls during development (not just GDPR, but potentially other standards such as ISO or PCI).

Accountability

“The controller shall be responsible for, and be able to demonstrate compliance with (the principles).”

The GDPR’s final principle is “accountability”. You must be able to show how you comply with the GDPR principles.

Accountability under the GDPR can take many forms. Here are some examples of accountability measures from an official EU advisory group:

  • Developing internal policies, procedures, and any other necessary documentation.
  • Conducting and documenting a GDPR data mapping exercise to identify how you collect, use, and share personal data.
  • Appointing a data protection officer (DPO) or designating a staff member to oversee privacy and data protection.
  • Maintaining a record of processing activities (RoPA) is a requirement under Article 30 of the GDPR.
  • Performing data protection impact assessments (DPIAs) or privacy impact assessments (PIAs) where appropriate.

The accountability principle is the only principle that applies to “data controllers” (who decide how and why to process personal data) but not “data processors” (who process personal data on behalf of a controller). 

If you offer an app or online service directly to your users, you’re likely a data controller. Controllers are accountable not only for themselves, but also for any processors they use (for example, analytics providers, advertisers, and cloud services can all be processors).

This means it’s essential to understand how you share personal data with third parties such as Google, Microsoft, or AWS. Measures such as privacy code scanning, RoPAs (Article 30 records), and data processing agreements can help you stay accountable under the GDPR.

Privado AI verifies consent and flags GDPR privacy risks

What are the penalties for violating the GDPR principles?

Violations of the basic GDPR principles can fall under the higher Article 83 fine tier. The maximum fine is €20 million or 4% of worldwide annual turnover from the previous financial year, whichever is higher. 

A supervisory authority can also issue warnings, reprimands, processing restrictions, suspension orders, or deletion requirements. The outcome depends on factors such as seriousness, duration, intent, mitigation, cooperation, affected data categories, and prior infringements.

Financial exposure is only one part of the risk. Weak evidence of compliance can delay product launches, increase remediation efforts, complicate contract reviews, and make it harder to answer regulatory or customer questions with confidence.

What can companies do to implement the GDPR principles in practice?

If you're deciding where to start, start with accountability. The other six principles describe what good processing looks like; accountability is the one that requires you to prove it, and in practice it's the one most programs fail first, not because the controls are missing, but because nobody can produce current evidence that they work. 

The following best practices help teams connect GDPR compliance with evidence from systems, policies, documentation, and live data flows.

Eight steps for applying Article 5 across product workflows

Build and maintain a data map

A data map documents what personal data your organization collects, where it flows, and who receives it. Without one, meeting purpose limitation, minimization, or accountability becomes guesswork.

Privado AI Dynamic Data Maps showing key elements Many companies build data maps using spreadsheets and questionnaires from engineering teams.

These methods are useful for gathering information, but they rely on people knowing about and reporting every system, integration, SDK, and processing activity.

Keeping the map accurate is often the harder part. Products change constantly as teams release new features, add vendors, update code, and introduce new data flows. When a data map is reviewed only at set intervals, it stops reflecting what is happening in the product.

The e-book Code Scanning Approach to Data Mapping explains how application-level code scanning can support these manual processes. 

Modern data management relies on dynamic data mapping that reads live processing activity across code, third-party integrations and cloud infrastructure. This approach captures data in motion, not only data at rest, and forms the backbone of a defensible Record of Processing Activities (RoPA).

Conduct regular Data Protection Impact Assessments (DPIA)

Article 35 requires a Data Protection Impact Assessment (DPIA) when processing is likely to result in a high risk to individuals' rights. The assessment should happen before processing begins, giving teams time to identify risks and put appropriate safeguards in place before launch.

Bringing DPIAs into the design and development process also helps privacy teams review risks while product decisions are still being made. AI-powered privacy assessments can automate intake, triage, and risk scoring, freeing your team from chasing stakeholders for questionnaire responses. That closes one of the biggest gaps in traditional GDPR programs, where DPIA backlogs stretch into months.

The e-book operationalizing privacy by design explains how assessments can be integrated into development workflows and refreshed as processing changes occur.

Automate consent monitoring and compliance verification

A Consent Management Platform (CMP) configures consent, but it does not always prove that trackers, pixels, or SDKs honor the user’s choice. Regulators have made clear that a working banner is not the same as a compliant one.

When we scanned 250 websites, 90% had at least one configuration that would likely breach GDPR or CCPA requirements. Most were running a CMP at the time.

Consent management platforms capture choices and apply configured rules. They were not designed to detect every compliance failure created when website data flows or third-party technologies change.

Consent monitoring adds that layer of verification. It scans your websites and mobile apps after every release. It flags pixels firing before consent, SDKs sharing personal data despite opt-out, and banners that violate local law. 

Continuous verification is fast becoming a baseline expectation across enterprise privacy programs guided by the GDPR data protection principles.

Webinar on monitoring privacy risks beyond CMP configuration

Privado AI’s Web Auditor and App Auditor verify whether consent banners, trackers, pixels, and SDKs behave as configured across relevant jurisdictions. 

Privado AI Web Monitor to check third-party activity on websites

The platform maps data flows by consent status and flags violations with supporting evidence. It can also generate developer tickets with remediation steps, helping privacy teams connect GDPR principles with the product workflows that actually need to change.

Prevent accidental data sharing with Privado AI App Monitor

Request a free Privado AI audit to verify compliance with consent requirements across your websites, mobile apps, trackers, and SDKs. 

Legal disclaimer: This article is for informational purposes only and does not constitute legal advice. GDPR interpretation, enforcement, and application vary by jurisdiction and by processing activity. Consult qualified counsel for guidance specific to your organization.

Frequently asked questions

What are the core principles of the GDPR?

Article 5 sets six processing principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; and integrity and confidentiality. Article 5(2) adds accountability, creating the commonly cited seven. Together, they govern how organizations collect, use, secure, retain and document personal data throughout each covered processing activity worldwide.

What is the GDPR in simple terms?

The GDPR is a European Union law governing how organizations process personal data. It requires a lawful basis, clear information, appropriate safeguards, and respect for individual rights. It can apply outside Europe when an organization offers goods or services to people in the EU or monitors their behavior there online.

Is GDPR only for EU citizens?

No. GDPR scope is based on establishment and processing activity, not citizenship alone. It protects people located in the European Union when covered organizations offer goods or services or monitor behavior there. It also applies to lawful processing connected with an EU establishment, regardless of where the processing takes place.

What are examples of GDPR?

Examples include obtaining valid consent for nonessential tracking, collecting only necessary account information, correcting inaccurate records, deleting data after a defined retention period, and documenting a DPIA for high-risk processing. Other practical examples include honoring access requests, securing data flows, maintaining current privacy notices, and documenting processing decisions for review.

What is not allowed under GDPR?

The GDPR does not allow organizations to process personal data without a lawful basis or hide material processing details. It prohibits incompatible reuse, excessive collection, hidden processing, or indefinite retention. Organizations cannot ignore rights, use weak security, retain data indefinitely, or rely on invalid consent when informed choice is required.

Industry insights you won’t delete. Delivered to your inbox.

Get regular updates from Privado AI

Request free website audit

Request Privado AI demo

Robert Bateman
Robert Bateman
Senior Partner at Privacy Partnership law firm
April 11, 2023
5
 mins read
Last Updated date
August 13, 2026

Get regular updates from Privado AI

Request free website audit

Request Privado AI demo

Continue Reading