01

The six principles of data processing

  • Lawfulness, fairness and transparency: processing must be lawful, fair and transparent towards the data subject.
  • Purpose limitation: data are collected for specified, explicit and legitimate purposes.
  • Data minimisation: only data that are adequate, relevant and necessary for the purpose are processed.
  • Accuracy: data must be accurate and kept up to date, with measures to correct or erase them.
  • Storage limitation: data are kept only for as long as necessary for the purpose.
  • Integrity and confidentiality: technical and organizational measures protect data from unauthorized processing or loss.

02

Who must demonstrate this

The controller is responsible for compliance with these principles and must be able to demonstrate it: this is the accountability principle. In practice, it means documenting purposes, legal bases and measures taken, so as to be able to respond to checks by authorities or data subjects.

03

How these principles apply day to day

Steps

  1. The controller gives the processor written instructions on the permitted operating methods.
  2. Persons authorized to process data commit to confidentiality or are subject to an equivalent legal obligation.
  3. The processor adopts appropriate technical and organizational measures to protect the data processed.
  4. The processor assists the controller in responding to data subject requests and in meeting security obligations.
  5. At the end of the service, the processor deletes or returns the data, unless retention is required by law.

04

Hypothetical example: customer invoicing

Hypothetical example: a company handling customer invoicing collects only the data necessary to issue invoices, applying minimisation, and keeps them only for the time required by the purpose, respecting storage limitation. If it entrusts processing to a cloud provider, it gives written instructions on permitted methods; the provider commits to confidentiality and protects the data with appropriate technical measures.

05

Checks to do before starting a processing activity

  • Verify that each processing activity has a specified, explicit and legitimate purpose.
  • Check that the data collected are adequate, relevant and limited to the purpose.
  • Set retention periods consistent with the purpose of the processing.
  • Document the written instructions given to processors.
  • Review the impact assessment whenever the risk level of the processing changes.

06

How to organize software support

A company can choose, together with its software partner, to set up a register of purposes and retention periods for each processing activity, distinct roles between those who decide purposes and those who carry out the processing, and traceability of instructions given to external suppliers. A periodic review process, linked to changes in risk, can be set up as an operational choice. These are suggested organizational options, not stated features of a specific product.

07

Common clarifications about the principles

  • Minimisation does not prevent collecting useful data, but requires limiting it to what is necessary for the stated purpose.
  • Accountability concerns the controller, who must be able to demonstrate compliance with the principles at all times.
  • The processor acts only on the controller's documented instructions, unless otherwise required by law.

08

Next step

Before starting or reviewing a personal data processing activity, map purposes, data collected and retention periods, and verify that instructions to suppliers are documented in writing.

FAQ

Frequently asked questions

What does the data minimisation principle mean in practice?

It means processing only personal data that are adequate, relevant and limited to what is necessary for the stated purpose, avoiding excessive collection.

Who must demonstrate compliance with the processing principles?

The controller is responsible for compliance with the principles and must be able to demonstrate it, under the accountability principle.

What must a processor do on behalf of the controller?

It must process data only on the controller's documented instructions, ensure confidentiality, adopt appropriate security measures, and at the end remove or return the data.

Sources and verification