CHAPTER IIPRINCIPLES

Article 5Principles relating to processing of personal data

Official text

(1)Personal data shall be:

(a)processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);

(b)collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89 (1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);

(c)adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);

(d)accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);

(e)kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);

(f)processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).

(2)The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).

Commentary

Article 5 is the cornerstone of the GDPR. Unlike the remaining provisions of the Regulation, which prescribe specific obligations, rights or procedural requirements, Article 5 establishes the fundamental principles that govern every processing activity involving personal data. These principles operate as the normative framework for the entire GDPR and influence the interpretation of every other provision, including the lawful bases for processing, data subject rights, security obligations, international data transfers and accountability.

Every controller must ensure that personal data is processed consistently with these principles throughout the entire data lifecycle, from the point of collection until the data is erased or anonymised. Compliance with Article 5 is therefore a continuous obligation rather than a one-time assessment undertaken when personal data is first collected.

Article 5 should be read together with Recitals 39, 50, 71 and 74, 79. These Recitals explain the objectives behind each processing principle and emphasise that controllers should adopt technical and organisational measures capable of ensuring and demonstrating compliance throughout the processing lifecycle.

The principles contained in Article 5 are deliberately drafted in broad language. Rather than prescribing exhaustive compliance rules, they establish legal standards that apply irrespective of technological developments or the particular business model adopted by an organisation. Consequently, the principles remain equally applicable to traditional paper records, cloud computing, artificial intelligence, machine learning, biometric technologies and future technologies that did not exist when the GDPR was adopted.

Article 5 consists of two distinct components.

  • Article 5(1) establishes the six substantive principles governing the processing of personal data.
  • Article 5(2) introduces the principle of accountability, requiring controllers not only to comply with those principles but also to demonstrate such compliance.

The principles contained in Article 5 are cumulative. Compliance with one principle does not excuse non-compliance with another. For example, processing supported by a lawful basis under Article 6 may nevertheless violate the GDPR if the processing is excessive, inaccurate, lacks transparency or continues beyond the permissible retention period.

Accordingly, supervisory authorities frequently rely upon Article 5 when assessing the overall legality of processing operations because it provides the benchmark against which every processing activity must ultimately be evaluated.

Article 5(1)(a): Lawfulness, Fairness and Transparency

  • Article 5(1)(a) provides that personal data shall be:

"processed lawfully, fairly and in a transparent manner in relation to the data subject."

Although these three requirements appear together within a single provision, they represent three independent legal obligations. Each addresses a different aspect of lawful processing.

Lawfulness concerns whether the controller has a valid legal basis permitting the processing. Fairness concerns whether the processing respects the legitimate interests, expectations and fundamental rights of the individual. Transparency concerns whether individuals are provided with sufficient information to understand how and why their personal data is being processed.

A controller must therefore satisfy all three requirements simultaneously. Compliance with one element cannot compensate for deficiencies in another.

Lawfulness

The principle of lawfulness requires every processing activity to be supported by an appropriate legal basis recognised under the GDPR. Processing cannot be undertaken merely because it is commercially desirable, administratively convenient or technologically possible.

The lawful bases are exhaustively listed in Article 6(1). Where processing involves special categories of personal data, controllers must additionally satisfy one of the conditions specified under Article 9.

Accordingly, before commencing any processing operation, a controller should determine:

  • the precise purpose for which personal data is being processed;
  • the applicable lawful basis under Article 6;
  • whether Article 9 is engaged;
  • whether any Member State legislation imposes additional conditions; and
  • whether the selected lawful basis accurately reflects the nature of the processing.

The lawful basis must exist before processing begins. Controllers should not collect personal data first and attempt to justify the processing later. Similarly, organisations should avoid selecting a lawful basis merely because it appears administratively convenient. Each lawful basis has distinct legal requirements and consequences, particularly regarding the exercise of data subject rights.

Example

processing based on consent enables individuals to withdraw that consent at any time, whereas processing based on legal obligation or performance of a contract operates under different legal conditions. Choosing the incorrect lawful basis may therefore undermine the legality of the entire processing activity.

Another important aspect of lawfulness is that the legal basis is purpose-specific. Different processing operations involving the same personal data may rely upon different lawful bases.

Illustration

A bank collects customer identification documents to comply with anti-money laundering legislation. This processing may rely upon compliance with a legal obligation under Article 6(1)(c). However, using the same documents to develop personalised financial marketing campaigns would require a separate lawful basis because the marketing purpose is distinct from the original statutory obligation. Controllers should therefore identify the lawful basis processing activity by processing activity, rather than assigning a single lawful basis to an entire database. Lawfulness must also be reviewed whenever the controller proposes to use personal data for a new purpose. Where the processing evolves beyond its original objective, controllers should assess whether the original lawful basis continues to apply or whether a fresh legal basis is required. This issue frequently arises where organisations introduce artificial intelligence tools, combine datasets collected for different purposes or repurpose historical customer information for analytics.

Fairness

The principle of fairness complements lawfulness by ensuring that processing does not produce unjustified or unexpected consequences for individuals.

Unlike Article 6, the GDPR does not define fairness. However, Recital 39 indicates that personal data should be processed in a manner that individuals can reasonably expect, having regard to the circumstances in which the data was collected and the relationship between the controller and the data subject.

Fairness therefore requires controllers to look beyond technical compliance and consider whether the processing treats individuals fairly in practice.

In assessing fairness, controllers should consider whether the processing:

  • is consistent with the purpose for which the personal data was originally collected;
  • respects the reasonable expectations of the data subject;
  • avoids misleading, deceptive or manipulative practices;
  • creates unjustified adverse effects upon individuals;
  • results in arbitrary discrimination or exclusion; or
  • disproportionately interferes with the rights and freedoms of the data subject.

The assessment is highly contextual. Processing that is fair in one situation may be unfair in another depending upon the nature of the relationship between the parties, the sensitivity of the information involved and the foreseeable consequences of the processing.

Example

employees, patients, children and financially vulnerable individuals often have limited bargaining power when interacting with organisations. Controllers should therefore exercise greater care when processing personal data relating to such individuals because they may not be in a position to meaningfully protect their own interests.

Fairness is particularly significant in the context of:

  • behavioural advertising;
  • algorithmic profiling;
  • artificial intelligence systems;
  • automated decision-making;
  • workplace monitoring;
  • facial recognition technologies; and
  • predictive analytics.

These technologies may comply with a lawful basis under Article 6 while nevertheless producing biased, opaque or disproportionate outcomes that conflict with the broader principle of fairness.

Illustration

An employer deploys AI software to assess employee productivity by continuously monitoring keyboard activity, application usage and webcam feeds throughout the working day. Even if the employer identifies a lawful basis for processing, the monitoring may still be unfair if it is excessively intrusive, disproportionate to the stated objective or extends beyond what employees could reasonably expect.

Transparency

The principle of transparency requires controllers to process personal data in a manner that is open, intelligible and easily understandable to the data subject. Transparency enables individuals to understand what personal data is collected, why it is collected, how it is used, who receives it, how long it is retained, and what rights they possess under the GDPR. Without adequate transparency, individuals cannot meaningfully exercise the rights conferred by the Regulation.

Transparency extends far beyond publishing a privacy notice. It requires controllers to communicate with data subjects throughout the processing lifecycle in a manner that is concise, accessible, accurate and free from unnecessary legal or technical complexity.

Recital 39 emphasises that individuals should be made aware of the risks, safeguards and rights associated with the processing of their personal data. Similarly, Articles 12 to 14 operationalise the transparency principle by prescribing the information that controllers must provide before or at the time personal data is collected.

Transparency applies throughout the processing lifecycle and therefore encompasses:

  • collection of personal data;
  • subsequent processing activities;
  • disclosures to third parties;
  • international data transfers;
  • automated decision-making and profiling;
  • changes in processing purposes; and
  • responses to requests made by data subjects.

Controllers should therefore view transparency as a continuing obligation rather than a document provided only at the point of collection.

Transparency requires meaningful information

The objective of transparency is not merely disclosure but understanding. Information should therefore enable an average individual to comprehend how the processing affects them and the choices available to them.

Accordingly, privacy notices should avoid:

  • vague or generic descriptions of processing;
  • blanket references to "business purposes";
  • excessive legal terminology;
  • technical language that ordinary individuals cannot understand; and
  • incomplete descriptions of recipients or processing purposes.

Instead, controllers should clearly explain:

  • the identity of the controller;
  • the categories of personal data collected;
  • the purposes of processing;
  • the lawful basis relied upon;
  • recipients or categories of recipients;
  • retention periods;
  • international transfers;
  • data subject rights; and
  • contact details for exercising those rights.

Where processing involves artificial intelligence, profiling or automated decision-making, transparency also requires controllers to provide meaningful information regarding the logic involved and the likely consequences of such processing where required by Articles 13, 14 and 22.

Layered transparency

The EDPB Guidelines on Transparency recognise that modern processing activities often involve complex information that cannot realistically be communicated within a single document.

Accordingly, controllers may adopt a layered privacy notice, whereby:

the first layer provides the most important information in concise language; subsequent layers provide more detailed legal and technical explanations; and additional information is made available through links or supplementary documents.

However, layering should improve accessibility rather than obscure important information. Controllers should not conceal essential processing information behind multiple webpages or require individuals to navigate complex websites before discovering how their personal data is processed.

Transparency and changes in processing

Transparency also requires controllers to inform individuals whenever personal data will be processed for a new purpose that was not originally communicated.

Simply updating a privacy notice without adequately informing existing users may not satisfy the transparency obligation where the new processing materially affects individuals.

Example

where an organisation introduces AI-powered profiling, behavioural advertising or cross-platform analytics after initially collecting personal data for basic service delivery, individuals should receive appropriate information explaining the new processing activity before it commences.

Practical Compliance Issues

Controllers frequently encounter practical difficulties when implementing the transparency principle.

Common compliance failures include:

  • publishing excessively lengthy privacy notices that individuals are unlikely to read;
  • relying upon vague statements such as "we may process your data for business purposes";
  • describing processing purposes too broadly;
  • failing to identify third-party recipients;
  • omitting retention periods;
  • using technical terminology without explanation; and
  • failing to notify individuals when processing purposes subsequently change.

Transparency is particularly challenging in AI systems because organisations may themselves have only a limited understanding of how highly complex machine-learning models generate particular outputs. Nevertheless, technical complexity does not diminish the controller's transparency obligations under the GDPR.

Article 5(1)(b): Purpose Limitation

Article 5(1)(b) provides that personal data shall be:

"collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes."

This principle is commonly referred to as the purpose limitation principle and represents one of the central safeguards against function creep, the gradual expansion of personal data processing beyond the reasons for which the data was originally collected.

Purpose limitation requires controllers to determine why personal data is required before collecting it. Personal data should not be collected merely because it may become useful in the future or because storage costs are inexpensive.

The principle therefore consists of two distinct obligations:

personal data must initially be collected for specified, explicit and legitimate purposes; and subsequent processing must remain compatible with those original purposes, unless a new lawful basis or another legal justification applies. "Specified" purposes

A purpose is specified where it is identified with sufficient precision before the processing begins.

Controllers should define the purpose clearly enough to determine:

  • why particular personal data is required;
  • what categories of personal data are necessary;
  • which lawful basis applies;
  • who should have access to the information; and
  • how long the information should be retained.

Generic descriptions such as:

  • improving business operations;
  • administrative purposes;
  • internal use; or
  • commercial activities,

are generally too broad to satisfy the requirement that purposes be specified.

Clearly defined purposes enable controllers to comply with several other GDPR obligations, including lawfulness, data minimisation, storage limitation and accountability.

"Explicit" purposes

The requirement that purposes be explicit complements the requirement that they be specified.

An explicit purpose is one that has been clearly communicated and documented, leaving little room for uncertainty regarding how personal data will be processed.

This serves two important functions.

First, it enables individuals to understand why their information is being collected.

Secondly, it prevents controllers from retrospectively redefining processing purposes after personal data has already been collected.

Controllers should therefore ensure that processing purposes are consistently reflected across:

  • privacy notices;
  • internal policies;
  • records of processing activities;
  • DPIAs;
  • processor agreements; and
  • contractual documentation.

Inconsistencies between these documents frequently indicate weaknesses in an organisation's governance framework and may attract regulatory scrutiny.

"Legitimate" purposes

The third element requires processing purposes to be legitimate.

Legitimacy extends beyond commercial desirability. A purpose may be commercially beneficial while nevertheless being unlawful, discriminatory or inconsistent with the objectives of the GDPR.

Whether a purpose is legitimate depends upon:

  • applicable Union or Member State law;
  • the rights and freedoms of individuals;
  • the context in which the personal data was collected; and
  • the broader objectives of the GDPR.

Controllers should therefore assess both the lawfulness of the processing and the legitimacy of the underlying purpose before commencing processing activities.

Illustration

A university collects students' contact information for academic administration and emergency communications. Subsequently selling that information to private coaching institutes for targeted advertising would be difficult to reconcile with the original educational purpose and would likely fail the purpose limitation principle unless an independent lawful basis and appropriate transparency measures existed.

Further processing and compatible purposes

Purpose limitation does not prohibit all subsequent processing.

Instead, the GDPR distinguishes between:

compatible further processing, which may continue under the original lawful basis; and incompatible further processing, which generally requires an independent legal justification.

Recital 50 and Article 6(4) provide the framework for assessing whether further processing is compatible with the original purpose.

The controller should consider factors such as:

  • the relationship between the original purpose and the proposed new purpose;
  • the context in which the personal data was collected;
  • the reasonable expectations of the data subject;
  • the nature and sensitivity of the personal data;
  • the possible consequences of the new processing; and
  • the existence of appropriate safeguards such as encryption or pseudonymisation.

This assessment requires a case-by-case evaluation. There is no universal rule determining whether further processing is compatible, and controllers should document their reasoning as part of their accountability obligations.

Compatible Further Processing

The GDPR recognises that organisations may legitimately need to use personal data for purposes that differ from those originally identified. However, such further processing is permissible only where it is compatible with the original purpose or where the controller identifies an independent lawful basis.

Article 6(4) sets out the compatibility assessment where the original processing was not based on consent or a legal obligation requiring a specific purpose. Controllers should evaluate:

  • the connection between the original and proposed purposes;
  • the context in which the personal data was collected;
  • the nature of the personal data;
  • the possible consequences for data subjects; and
  • the existence of appropriate safeguards such as encryption or pseudonymisation.

This assessment prevents organisations from gradually expanding the use of personal data beyond what individuals reasonably expected when the data was collected.

Processing Presumed to be Compatible

Article 5(1)(b), read with Recital 50, recognises that further processing for archiving in the public interest, scientific or historical research, and statistical purposes is generally not regarded as incompatible with the original purpose, provided that appropriate safeguards under Article 89 are implemented.

This does not create an unrestricted exemption. Controllers must still comply with the remaining GDPR principles, particularly data minimisation, storage limitation, security and accountability.

Illustration

A hospital collects patient records to provide medical treatment. Subsequently using anonymised or appropriately safeguarded patient information for medical research may constitute compatible further processing where the requirements of Article 89 are satisfied.

Article 5(1)(c): Data Minimisation

Article 5(1)(c) requires that personal data shall be:

"adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed."

The principle of data minimisation requires controllers to process only the personal data genuinely necessary for achieving the identified purpose. It reflects the broader objective of reducing privacy risks by limiting unnecessary collection, storage and use of personal information.

The provision contains three cumulative requirements.

  • Adequate

The personal data collected should be sufficient to achieve the intended processing purpose.

Collecting too little information may prevent the controller from performing its legitimate function effectively.

Example

an airline requires passenger identity information to comply with aviation security requirements. Collecting only a passenger's first name would be inadequate for that purpose.

  • Relevant

The personal data must have a rational connection with the identified processing purpose.

Information should not be collected merely because it may become useful in the future or because storage is inexpensive.

Controllers should therefore ask:

Does this information contribute to achieving the stated purpose? Would the processing objective still be achieved without collecting this information?

Where the answer is yes, collection of the additional information may not be justified.

  • Limited to What is Necessary

Necessity is the central element of the minimisation principle.

Controllers should collect the least amount of personal data reasonably required to achieve the specified purpose.

This does not require controllers to collect the smallest amount of information conceivable. Rather, the collection should be proportionate and objectively necessary having regard to the processing objective.

Practical Compliance Issues

Data minimisation is frequently overlooked because organisations often adopt a "collect everything" approach.

Common compliance failures include:

  • mandatory collection of optional information;
  • requesting identity documents where simpler verification methods would suffice;
  • excessive employee monitoring;
  • indiscriminate CCTV coverage;
  • collecting precise geolocation when approximate location would be sufficient; and
  • retaining historical customer information that is no longer required.

Illustration

A hotel requests guests' passport details where required for legal compliance. However, requiring guests to disclose their marital status, religion and social media accounts as a mandatory condition of booking would ordinarily exceed what is necessary for providing accommodation services.

Article 5(1)(d): Accuracy

Article 5(1)(d) provides that personal data shall be:

"accurate and, where necessary, kept up to date."

The principle recognises that inaccurate personal data may adversely affect individuals and lead to unfair decisions.

Controllers must therefore take every reasonable step to ensure that inaccurate personal data is corrected or erased without undue delay.

Accuracy is an ongoing obligation.

Personal data that was accurate when originally collected may subsequently become inaccurate because of:

  • changes of address;
  • changes in employment;
  • changes in financial circumstances;
  • updated medical information;
  • expired identity documents; or
  • outdated contact details.

Controllers should therefore establish procedures enabling individuals to update their information and should periodically verify the accuracy of information where appropriate.

The required standard depends upon the nature of the processing.

Example

healthcare providers and credit reference agencies are generally expected to maintain a higher level of accuracy than organisations maintaining low-risk marketing databases because inaccurate records in those sectors may produce significant consequences.

Article 5(1)(e): Storage Limitation

Article 5(1)(e) provides that personal data shall be:

"kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed."

The storage limitation principle prohibits indefinite retention of personal data.

Controllers should determine appropriate retention periods before collecting personal data rather than retaining information indefinitely.

Retention periods should be based upon:

  • legal obligations;
  • contractual requirements;
  • regulatory guidance;
  • limitation periods;
  • business necessity; and
  • the original processing purpose.

Where the purpose has been fulfilled and no legal obligation requires continued retention, the personal data should ordinarily be:

  • erased;
  • anonymised; or
  • irreversibly aggregated.

Storage limitation should be distinguished from deletion obligations under national law. Controllers may retain personal data for longer periods where required by Union or Member State legislation, litigation holds, taxation requirements or statutory record-keeping obligations.

Article 5(1)(f) requires personal data to be processed:

"in a manner that ensures appropriate security of the personal data."

This principle is commonly referred to as the security principle.

Controllers must protect personal data against:

  • unauthorised access;
  • accidental disclosure;
  • unlawful processing;
  • accidental destruction;
  • loss; and
  • damage.

The GDPR deliberately avoids prescribing specific security technologies.

Instead, Article 32 adopts a risk-based approach, requiring security measures appropriate to the nature, scope, context and risks of the processing.

Depending upon the circumstances, appropriate measures may include:

  • encryption;
  • pseudonymisation;
  • access controls;
  • multi-factor authentication;
  • network monitoring;
  • secure backups;
  • disaster recovery planning;
  • employee training; and
  • incident response procedures.

Security is not solely an IT responsibility.

Many personal data breaches arise from:

  • human error;
  • phishing attacks;
  • poor access management;
  • insecure disposal of documents;
  • misconfigured cloud services; and
  • inadequate vendor oversight.

Controllers should therefore combine technical safeguards with organisational measures and regular staff awareness programmes.

Article 5(2): Accountability

Article 5(2) provides:

"The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1."

This is one of the most significant provisions of the GDPR.

Accountability transforms Article 5 from a set of abstract principles into demonstrable legal obligations.

Controllers must therefore do more than comply-they must be capable of proving compliance.

The burden of demonstrating compliance rests with the controller.

Accordingly, organisations should maintain evidence including:

  • Records of Processing Activities (Article 30);
  • privacy notices;
  • lawful basis assessments;
  • Legitimate Interest Assessments (where applicable);
  • Data Protection Impact Assessments;
  • retention schedules;
  • information security policies;
  • processor agreements;
  • breach registers;
  • staff training records; and
  • internal audits.

Controllers should therefore regard accountability as a governance framework rather than a documentation exercise.