Seven principles,
and the evidence for each.
The GDPR principles in Article 5 are the test every use of personal data has to pass, and the first thing a regulator checks. This guide explains each one in practical terms, what privacy by design and by default require under Article 25, and how the rest of the GDPR's requirements hang off them. Not legal advice.
Last updated Published by TryTrustableNot legal advice
The GDPR principles are the seven rules in Article 5 that every use of personal data must meet: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The first six are in Article 5(1). Accountability, in Article 5(2), makes the controller responsible for meeting them and able to demonstrate it. Every other GDPR requirement, from consent to breach notification, is a more specific way of applying these seven.
What are the seven GDPR principles?
Article 5 of the GDPR sets out six principles for how personal data is processed and a seventh, accountability, that makes you answerable for the other six. They apply to every controller, whatever its size, and they are written broadly on purpose: when no specific rule covers a situation, the principles still do. The UK GDPR keeps the same seven.
| Principle | Article | What it means in practice | Evidence you can show |
|---|---|---|---|
| Lawfulness, fairness and transparency | 5(1)(a) | A lawful basis under Article 6 for each purpose, no processing people would not reasonably expect, and a clear notice | Privacy notice, lawful basis per purpose, consent records |
| Purpose limitation | 5(1)(b) | Collect for specified, explicit purposes; do not reuse in a way incompatible with them | Record of processing activities with purposes |
| Data minimisation | 5(1)(c) | Adequate, relevant and limited to what is necessary for the purpose | Field-level justification for forms and data stores |
| Accuracy | 5(1)(d) | Accurate and up to date where necessary; correct or erase inaccurate data without delay | Self-service profile editing, rectification log |
| Storage limitation | 5(1)(e) | Kept in identifiable form no longer than necessary | Retention schedule and deletion records |
| Integrity and confidentiality | 5(1)(f) | Appropriate security against unauthorised processing, loss, destruction or damage | Access control, encryption, logging, incident records |
| Accountability | 5(2) | Be responsible for the six above and able to demonstrate it | Policies, records, DPIAs, audits, training, contracts |
The wording follows Article 5. Breaching the principles falls in the higher fine tier of Article 83(5).
Lawfulness, fairness and transparency
Lawful means you have one of the six bases in Article 6 for each purpose, and meet any other law that applies. Fair means you do not use data in ways people would not reasonably expect or that harm them unjustifiably, even where a basis exists. Transparent means telling people, at the time you collect their data, who you are, why you want it and what they can do about it. A cookie banner that loads analytics before anyone clicks is a common way to fall short here, and of the ePrivacy rules on cookies. See our consent guide.
Purpose limitation
Decide and write down why you collect each piece of data before you collect it. Further use is allowed only where it is compatible with the original purpose; archiving in the public interest, research and statistics are treated as compatible under Article 89(1) safeguards. A new purpose that is not compatible needs its own basis, and usually a new notice. Training a model on support tickets collected to answer support questions is a question you should ask before, not after.
What is data minimisation under GDPR?
Data minimisation means personal data must be adequate, relevant and limited to what is necessary for the purpose (Article 5(1)(c)). Necessary is the operative word: not useful, not possibly useful later. In practice:
- Justify each field on each form. If you cannot say what a date of birth is for, stop asking for it.
- Default to less: pseudonymise analytics, truncate IP addresses, collect an age band rather than a birth date where that is enough.
- Limit who can see the data as well as how much is collected; Article 25(2) counts accessibility as part of minimisation.
- Check third-party scripts. A tag that sends full page URLs with email addresses in query strings is a minimisation failure you did not write.
Accuracy and storage limitation (data retention)
Accuracy requires every reasonable step to correct or erase inaccurate data without delay, having regard to the purpose; the right to rectification in Article 16 is the person's side of the same duty. Storage limitation is the GDPR's data retention rule: keep data in identifiable form only as long as the purpose needs it. The GDPR sets no fixed periods. You set them, write them in a retention schedule, and then actually delete or anonymise on time. Other law often sets a minimum, such as tax records, and that is a legitimate reason to keep data longer for that purpose only.
Integrity and confidentiality (security)
Article 5(1)(f) requires appropriate security, and Article 32 says what appropriate means: measures matched to the risk, such as pseudonymisation and encryption, resilience, the ability to restore access after an incident, and regular testing. If you already run SOC 2 or ISO 27001 controls, most of the work is done; the gap is usually mapping it to personal data and having a breach process that meets the 72-hour notification rule in Article 33. See incident management.
Accountability: proving you comply
Accountability turns the principles from intentions into evidence. Article 5(2) makes the controller responsible for compliance and able to demonstrate it, and Article 24 requires appropriate measures, including policies, to do so. The documents a regulator or enterprise customer will ask for: a record of processing activities, privacy notices, consent records, processor contracts, DPIAs, a breach log, training records and the results of your own checks. If it is not written down, it will be hard to show it happened.
What is privacy by design and by default (Article 25)?
Article 25 makes the principles an engineering requirement. By design (Article 25(1)): both when you decide how to process data and while you process it, implement appropriate technical and organisational measures, such as pseudonymisation, designed to put the principles into effect, taking into account the state of the art, cost, the nature and purpose of the processing and the risks. By default (Article 25(2)): only the data necessary for each specific purpose is processed, and that applies to how much you collect, how far you process it, how long you keep it and who can access it. By default, personal data must not be made accessible to an indefinite number of people without the individual's intervention.
The EDPB's Guidelines 4/2019 are the EU reference on what this means in practice. In the UK, the Data (Use and Access) Act 2025 adds that online services likely to be used by children must take children's needs into account, and the ICO has updated its by-design guidance to match. Article 25 sits in the lower fine tier of Article 83(4): up to EUR 10 million or 2% of worldwide annual turnover, whichever is higher.
Privacy by design principles: the seven foundational principles
The phrase predates the GDPR. Ann Cavoukian, as Information and Privacy Commissioner of Ontario, set out seven foundational principles that many teams still use as a design checklist: proactive not reactive, preventative not remedial; privacy as the default setting; privacy embedded into design; full functionality, positive-sum not zero-sum; end-to-end security across the whole lifecycle; visibility and transparency; and respect for user privacy. They are a framework, not law. The legal duty in the EU and UK is Article 25, and that is what you will be assessed against.
GDPR requirements: how they map to the principles
Most specific GDPR requirements are one or more principles made concrete. Read together, this is the outline of a GDPR programme. Not sure the GDPR reaches you at all? Try the GDPR applicability checker.
| Requirement | Article | Principle it serves |
|---|---|---|
| Have a lawful basis for each purpose | 6 | Lawfulness |
| Consent that is freely given, specific, informed and as easy to withdraw as to give | 7 | Lawfulness, fairness |
| Extra conditions for special category data | 9 | Lawfulness |
| Tell people what you do with their data | 13, 14 | Transparency |
| Answer rights requests within one month | 12, 15 to 22 | Transparency, accuracy |
| Appoint an EU or UK representative if you have no establishment there | 27 | Accountability |
| Bind processors by contract | 28 | Integrity, accountability |
| Keep a record of processing activities | 30 | Accountability |
| Secure the processing | 32 | Integrity and confidentiality |
| Report personal data breaches within 72 hours where required | 33, 34 | Integrity, accountability |
| Run a DPIA for high-risk processing | 35 | Accountability |
| Designate a DPO where Article 37 requires one | 37 | Accountability |
| Protect data transferred outside the EEA | 44 to 49 | All of them, abroad |
An overview, not a complete list. Member State law and sector rules add more.
Where TryTrustable fits
The principles are judgement calls you make once and then have to evidence for years. The platform holds that evidence, and maps each control across GDPR, UK GDPR and the other frameworks you run so one piece of work counts everywhere. See GDPR for SaaS for the full programme.
| Principle | Where TryTrustable helps |
|---|---|
| Lawfulness and transparency | A consent banner that blocks trackers until the visitor chooses, with each notice version recorded; free privacy policy and cookie policy generators |
| Purpose limitation | Consent recorded per purpose, and withdrawals sent to each processor's webhook with every delivery logged |
| Minimisation | The free cookie scanner shows which trackers fire before consent |
| Accuracy and storage limitation | A rights queue for correction and erasure requests, with deadlines set at receipt |
| Integrity and confidentiality | Security controls mapped once across GDPR, ISO 27001 and SOC 2, with evidence from GitHub, AWS and GCP |
| Accountability | A tamper-evident consent ledger, evidence ledger, policies, risk register and vendor register, all in one place an auditor can read |
Tools that hold the evidence. The decisions about purposes, bases and retention stay with you.
The things people ask us
What are the 7 principles of GDPR?
Lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. They are in Article 5 of the GDPR and the UK GDPR.
Which GDPR principle covers data retention?
Storage limitation, Article 5(1)(e): keep data in a form that identifies people for no longer than the purpose needs. The GDPR does not set fixed periods; you set and justify them.
What is the difference between privacy by design and privacy by default?
By design means building measures into how you process data so the principles are met. By default means the settings, out of the box, process only what each purpose needs, and do not expose data to an indefinite number of people without the person's action.
Is accountability a GDPR principle?
Yes. Article 5(2) makes the controller responsible for complying with the other principles and able to demonstrate that it does.
What is the fine for breaching the GDPR principles?
Infringements of Article 5 fall under Article 83(5): up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher. Our GDPR fine calculator shows the ceiling for your turnover.
Are the UK GDPR principles different?
No. The UK GDPR keeps the same seven principles in Article 5. The Data (Use and Access) Act 2025 changed other parts of UK law, such as lawful bases and children's online services.
Turn the seven principles into evidence you can show.
Thirty minutes on your consent records, processing register and the GDPR and UK GDPR controls you already run.