01

The six principles of Article 5 of the GDPR

Article 5 of the GDPR establishes that personal data must be processed lawfully, fairly, and transparently; collected for specified and explicit purposes; adequate and limited to what is necessary; accurate and kept up to date when needed; kept only for as long as necessary for the stated purposes; and protected with appropriate technical and organizational measures against unauthorized processing, loss, or destruction.

These six criteria — lawfulness/fairness/transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity and confidentiality — form the basis on which to build every business process involving personal data.

02

Accountability as a guiding principle

The GDPR adds a seventh element, accountability: the data controller must be able to demonstrate, not just assert, compliance with the principles listed. This means documenting choices, reasons, and measures taken, not simply applying them.

03

How to translate the principles into a business process

Steps

  1. Define in writing the purposes of each processing activity before collecting personal data.
  2. Collect only data that is adequate and necessary for the stated purpose.
  3. Assign responsibility for periodically checking the accuracy of stored data.
  4. Establish retention periods consistent with the purposes and delete data no longer needed.
  5. Document the security measures adopted to demonstrate accountability.

04

A hypothetical case

Hypothesis: a company collects candidates' email addresses for an interview. Applying the principles, it retains only the data necessary for selection (minimization), informs candidates about the intended use (transparency), and deletes the data of unselected candidates after a defined period (storage limitation), documenting the choice to demonstrate accountability.

05

What to check regularly

  • The stated purposes still match the data actually processed.
  • The stored data is up to date and inaccuracies are corrected without delay.
  • Retention periods are respected and unnecessary data is deleted.
  • Security measures remain appropriate to the risk, with review when the risk changes.
  • If external processors are used, the contract includes documented instructions and confidentiality obligations.

06

How software can support these principles

A company may choose to configure, with its software partner, a register of processing purposes, clear roles for who decides what to collect and for how long, and a documentary trail of decisions made to demonstrate accountability. These are suggested operational choices, not specific product features.

For relationships with suppliers who process data on the company's behalf, it is useful to include contractual clauses referring to documented instructions, confidentiality obligations, and cooperation in the event of checks, so that it is easy to trace who processed which data and why.

07

Frequently asked questions about GDPR principles

  • The six principles apply to any type of personal data processed by the company, regardless of sector.
  • Accountability requires being able to demonstrate, with documentation, compliance with the principles, not just declaring it.
  • Reviewing security measures is advisable when the level of risk associated with the processing changes.

08

Next step

A good starting point is to map the personal data processing activities active in the company and check, for each one, whether it complies with the six principles of Article 5 and whether accountability is documented.

FAQ

Frequently asked questions

What are the six principles of personal data processing under the GDPR?

They are lawfulness/fairness/transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity/confidentiality, as established by Article 5 of the GDPR.

What does 'accountability' mean under the GDPR?

It means that the data controller must be able to demonstrate, with concrete documentation, compliance with the processing principles, not just apply them.

When should a data protection impact assessment be reassessed?

The controller carries out a review when variations arise in the risk represented by the processing activities, to check consistency with the assessment carried out.

Sources and verification