Article 5 is the cornerstone of the GDPR. Unlike the remaining provisions of the Regulation, which prescribe specific obligations, rights or procedural requirements, Article 5 establishes the fundamental principles that govern every processing activity involving personal data. These principles operate as the normative framework for the entire GDPR and influence the interpretation of every other provision, including the lawful bases for processing, data subject rights, security obligations, international data transfers and accountability.
Every controller must ensure that personal data is processed consistently with these principles throughout the entire data lifecycle, from the point of collection until the data is erased or anonymised. Compliance with Article 5 is therefore a continuous obligation rather than a one-time assessment undertaken when personal data is first collected.
Article 5 should be read together with Recitals 39, 50, 71 and 74, 79. These Recitals explain the objectives behind each processing principle and emphasise that controllers should adopt technical and organisational measures capable of ensuring and demonstrating compliance throughout the processing lifecycle.
The principles contained in Article 5 are deliberately drafted in broad language. Rather than prescribing exhaustive compliance rules, they establish legal standards that apply irrespective of technological developments or the particular business model adopted by an organisation. Consequently, the principles remain equally applicable to traditional paper records, cloud computing, artificial intelligence, machine learning, biometric technologies and future technologies that did not exist when the GDPR was adopted.
Article 5 consists of two distinct components.
- Article 5(1) establishes the six substantive principles governing the processing of personal data.
- Article 5(2) introduces the principle of accountability, requiring controllers not only to comply with those principles but also to demonstrate such compliance.
The principles contained in Article 5 are cumulative. Compliance with one principle does not excuse non-compliance with another. For example, processing supported by a lawful basis under Article 6 may nevertheless violate the GDPR if the processing is excessive, inaccurate, lacks transparency or continues beyond the permissible retention period.
Accordingly, supervisory authorities frequently rely upon Article 5 when assessing the overall legality of processing operations because it provides the benchmark against which every processing activity must ultimately be evaluated.