01
What Article 5 of the GDPR says
Regulation (EU) 2016/679 states that personal data must be processed lawfully, fairly and transparently, for specified and explicit purposes, and limited to what is necessary in relation to those purposes (citation-1, citation-3).
The same data must be accurate, kept only for as long as necessary, and protected with appropriate technical and organizational measures against unauthorized processing or accidental loss; the data controller is responsible for demonstrating compliance with these principles, under the accountability principle (citation-1, citation-3).
02
Why accountability changes the way of working
Paragraph 2 of Article 5 introduces accountability: it is not enough to comply with the principles, one must be able to demonstrate it (citation-2, citation-3). Every choice about collecting, using, and retaining data must leave a verifiable trail, useful in case of an audit and for sounder internal decisions.
03
How to apply the principles in daily work
Steps
- Define a specified and explicit purpose for each processing activity before collecting data (citation-1).
- Collect only data that is adequate and relevant to that purpose, avoiding unnecessary fields (citation-1).
- Set a retention period consistent with the purpose and periodically review data no longer needed (citation-1).
- Document the technical and organizational measures adopted to ensure integrity and confidentiality, so they can be demonstrated (citation-3, citation-2).
04
A hypothetical case: data collection for a loyalty program
Hypothetical example: a company launching a loyalty program collects name, email, and purchase history for a marketing purpose stated at sign-up. Applying the principles of Article 5, it limits data to what is necessary, avoids reusing it for purposes incompatible with the original one, and sets a deletion date for inactive customers, documenting the choices so they can be demonstrated (citation-1, citation-3).
05
Checklist to review ongoing processing activities
- Is the purpose of the processing written down, specified, and explicit? (citation-1)
- Is the data collected limited to what is necessary for that purpose? (citation-1)
- Is there a defined and applied retention period? (citation-1)
- Are the security measures adopted documented and kept up to date? (citation-3)
- Can compliance with the principles be demonstrated upon request? (citation-2)
06
What a management software can help oversee on these principles
A company can ask its software provider to make visible, for each configured processing activity, the stated purpose, the roles involved, and the planned retention periods, so as to maintain a trail consistent with the principles of Article 5 (citation-1, citation-3). It is also a useful operational choice to distinguish within the system who acts as controller and who as processor, mirroring in the role design the documented instructions and assistance obligations required of the processor (citation-4).
07
Frequently asked questions about processing principles
- Does the minimization principle forbid every optional field? No: it forbids collecting data that is not adequate or relevant to the stated purpose (citation-1).
- Does accountability only require internal procedures? It requires that the controller be able to demonstrate compliance with the principles, not just apply them (citation-2, citation-3).
- Can data remain stored indefinitely for statistical purposes? Only with the technical and organizational measures required by the regulation to protect data subjects (citation-1).
08
The next practical step
A good starting point is to map existing processing activities, noting purpose, data collected, retention periods, and designated responsible party, then to check which principles of Article 5 are already met and which need attention (citation-1, citation-3).
FAQ
Frequently asked questions
What are the six principles of Article 5 of the GDPR?
Lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality. In addition, there is accountability, which requires demonstrating compliance with the other principles (citation-1, citation-3).
What does the minimization principle mean in practice?
It means collecting only data that is adequate, relevant, and limited to what is necessary for the stated purpose, avoiding unnecessary fields or information (citation-1).
Who must demonstrate compliance with the GDPR principles?
The data controller is responsible for compliance with the principles of Article 5 and must be able to demonstrate it, under the accountability principle (citation-2, citation-3).
✓