What are the seven principles in GDPR Article 5?
Article 5 of the GDPR sets six principles for processing personal data: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality. Article 5(2) adds a seventh, accountability, which makes the controller responsible for and able to demonstrate compliance with the other six.
Applies to: Every controller within the scope of the GDPR, since Article 5 governs all processing of personal data and Article 5(2) places the burden of demonstrating compliance on the controller.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanArticle 5 is the shortest route to understanding what the GDPR is actually asking of you. Almost every other obligation in the Regulation is a mechanism for delivering one of these principles, and enforcement decisions routinely cite Article 5 alongside whatever specific article was breached.
The six principles in Article 5(1)
The article opens with three words that set the frame: personal data shall be. What follows are conditions on the data itself, not merely on your paperwork.
(a) Lawfulness, fairness and transparency. Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject. Lawfulness points to Article 6; fairness and transparency are separate tests that a technically valid lawful basis does not satisfy on its own.
(b) Purpose limitation. Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. The text adds that further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered incompatible with the initial purposes.
Note "incompatible", not "different". The principle does not freeze data to a single use; it bars uses that conflict with the one you declared.
(c) Data minimisation. Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Three tests, and "adequate" runs in the opposite direction from the other two: collecting too little to do the job properly is also a failure.
(d) Accuracy. Accurate and, where necessary, kept up to date, with every reasonable step taken to ensure that inaccurate personal data are erased or rectified without delay, having regard to the purposes. The standard is tied to purpose, so an outdated address matters more in a billing system than in an archived support log.
(e) Storage limitation. Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes. Longer storage is allowed insofar as the data will be processed solely for Article 89(1) purposes, subject to appropriate technical and organisational measures.
The wording is precise and often misread. The principle limits how long you keep data in an identifiable form, which is why anonymisation is an alternative to deletion.
(f) Integrity and confidentiality. Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures. This is the principle that Article 32 then builds out in detail.
The seventh: accountability
Article 5(2): the controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1.
That short sentence changes the character of the whole Regulation. Under it, doing the right thing and being unable to evidence it is a compliance failure. It is why the record of processing activities exists, why impact assessments are written down, and why "we have always deleted old accounts" is a weaker answer than a retention schedule with dated reviews.
Why the principles get cited in enforcement
Regulators reach for Article 5 because it applies to the whole of a processing operation rather than to one step. A retention failure is Article 5(1)(e). Collecting more than you need is Article 5(1)(c). A breach caused by weak controls is Article 5(1)(f) as well as Article 32. And in most decisions Article 5(2) comes along too, because a controller that cannot produce documentation has failed the accountability principle regardless of what it actually did.
A practical way to use them
Take one processing activity, in a real system, and answer six questions about it. What is the purpose, and where did we state it. What is the lawful basis. Which fields are genuinely necessary for that purpose. How do we correct data that is wrong. When does this data stop being identifiable. What protects it. Then ask the seventh: where is the evidence of all of the above.
Teams that run this on their three highest-volume data flows usually find the same two gaps, retention and minimisation, and those are exactly the gaps that show up in enforcement.
Next step
The principles apply to whoever is in scope, and scope is where most businesses guess. The free 2-minute Obligation Scan checks your business against GDPR and every US state privacy law at once and tells you which obligations actually reach you. For the lawful basis question underneath Article 5(1)(a), see GDPR Article 6, and for the surrounding duties see the GDPR compliance pillar.
Compliance checklist
- Map each processing activity to a purpose that is specified, explicit and legitimate, as Article 5(1)(b) requires, and check that later uses are not incompatible with it.
- Test every field you collect against Article 5(1)(c): adequate, relevant and limited to what is necessary for the purpose. Fields collected 'in case we need them later' fail this.
- Set a retention period or the criteria for one for each category of data, because Article 5(1)(e) permits identification only for as long as is necessary.
- Build a correction path, since Article 5(1)(d) requires every reasonable step to erase or rectify inaccurate personal data without delay.
- Document the lawful basis and the transparency you provide, so that Article 5(1)(a) can be evidenced rather than asserted.
- Keep the records that make Article 5(2) demonstrable, since accountability is judged on what you can show rather than on what you did quietly.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 5 (principles relating to processing of personal data), consolidated official text on EUR-Lex
- Regulation (EU) 2016/679 (GDPR), Article 89(1) (safeguards for archiving, research and statistical purposes), EUR-Lex
Last verified: 2026-08-28
Informational, not legal advice.