GDPR principles

Seven principles,
and the evidence for each.

The GDPR principles in Article 5 are the test every use of personal data has to pass, and the first thing a regulator checks. This guide explains each one in practical terms, what privacy by design and by default require under Article 25, and how the rest of the GDPR's requirements hang off them. Not legal advice.

GDPR Art. 5Art. 25UK GDPREDPB Guidelines 4/2019

Last updated Published by TryTrustableNot legal advice

Short answer

The GDPR principles are the seven rules in Article 5 that every use of personal data must meet: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The first six are in Article 5(1). Accountability, in Article 5(2), makes the controller responsible for meeting them and able to demonstrate it. Every other GDPR requirement, from consent to breach notification, is a more specific way of applying these seven.

01

What are the seven GDPR principles?

Article 5 of the GDPR sets out six principles for how personal data is processed and a seventh, accountability, that makes you answerable for the other six. They apply to every controller, whatever its size, and they are written broadly on purpose: when no specific rule covers a situation, the principles still do. The UK GDPR keeps the same seven.

PrincipleArticleWhat it means in practiceEvidence you can show
Lawfulness, fairness and transparency5(1)(a)A lawful basis under Article 6 for each purpose, no processing people would not reasonably expect, and a clear noticePrivacy notice, lawful basis per purpose, consent records
Purpose limitation5(1)(b)Collect for specified, explicit purposes; do not reuse in a way incompatible with themRecord of processing activities with purposes
Data minimisation5(1)(c)Adequate, relevant and limited to what is necessary for the purposeField-level justification for forms and data stores
Accuracy5(1)(d)Accurate and up to date where necessary; correct or erase inaccurate data without delaySelf-service profile editing, rectification log
Storage limitation5(1)(e)Kept in identifiable form no longer than necessaryRetention schedule and deletion records
Integrity and confidentiality5(1)(f)Appropriate security against unauthorised processing, loss, destruction or damageAccess control, encryption, logging, incident records
Accountability5(2)Be responsible for the six above and able to demonstrate itPolicies, records, DPIAs, audits, training, contracts

The wording follows Article 5. Breaching the principles falls in the higher fine tier of Article 83(5).

02

Lawfulness, fairness and transparency

Lawful means you have one of the six bases in Article 6 for each purpose, and meet any other law that applies. Fair means you do not use data in ways people would not reasonably expect or that harm them unjustifiably, even where a basis exists. Transparent means telling people, at the time you collect their data, who you are, why you want it and what they can do about it. A cookie banner that loads analytics before anyone clicks is a common way to fall short here, and of the ePrivacy rules on cookies. See our consent guide.

03

Purpose limitation

Decide and write down why you collect each piece of data before you collect it. Further use is allowed only where it is compatible with the original purpose; archiving in the public interest, research and statistics are treated as compatible under Article 89(1) safeguards. A new purpose that is not compatible needs its own basis, and usually a new notice. Training a model on support tickets collected to answer support questions is a question you should ask before, not after.

04

What is data minimisation under GDPR?

Data minimisation means personal data must be adequate, relevant and limited to what is necessary for the purpose (Article 5(1)(c)). Necessary is the operative word: not useful, not possibly useful later. In practice:

  • Justify each field on each form. If you cannot say what a date of birth is for, stop asking for it.
  • Default to less: pseudonymise analytics, truncate IP addresses, collect an age band rather than a birth date where that is enough.
  • Limit who can see the data as well as how much is collected; Article 25(2) counts accessibility as part of minimisation.
  • Check third-party scripts. A tag that sends full page URLs with email addresses in query strings is a minimisation failure you did not write.
05

Accuracy and storage limitation (data retention)

Accuracy requires every reasonable step to correct or erase inaccurate data without delay, having regard to the purpose; the right to rectification in Article 16 is the person's side of the same duty. Storage limitation is the GDPR's data retention rule: keep data in identifiable form only as long as the purpose needs it. The GDPR sets no fixed periods. You set them, write them in a retention schedule, and then actually delete or anonymise on time. Other law often sets a minimum, such as tax records, and that is a legitimate reason to keep data longer for that purpose only.

06

Integrity and confidentiality (security)

Article 5(1)(f) requires appropriate security, and Article 32 says what appropriate means: measures matched to the risk, such as pseudonymisation and encryption, resilience, the ability to restore access after an incident, and regular testing. If you already run SOC 2 or ISO 27001 controls, most of the work is done; the gap is usually mapping it to personal data and having a breach process that meets the 72-hour notification rule in Article 33. See incident management.

07

Accountability: proving you comply

Accountability turns the principles from intentions into evidence. Article 5(2) makes the controller responsible for compliance and able to demonstrate it, and Article 24 requires appropriate measures, including policies, to do so. The documents a regulator or enterprise customer will ask for: a record of processing activities, privacy notices, consent records, processor contracts, DPIAs, a breach log, training records and the results of your own checks. If it is not written down, it will be hard to show it happened.

08

What is privacy by design and by default (Article 25)?

Article 25 makes the principles an engineering requirement. By design (Article 25(1)): both when you decide how to process data and while you process it, implement appropriate technical and organisational measures, such as pseudonymisation, designed to put the principles into effect, taking into account the state of the art, cost, the nature and purpose of the processing and the risks. By default (Article 25(2)): only the data necessary for each specific purpose is processed, and that applies to how much you collect, how far you process it, how long you keep it and who can access it. By default, personal data must not be made accessible to an indefinite number of people without the individual's intervention.

The EDPB's Guidelines 4/2019 are the EU reference on what this means in practice. In the UK, the Data (Use and Access) Act 2025 adds that online services likely to be used by children must take children's needs into account, and the ICO has updated its by-design guidance to match. Article 25 sits in the lower fine tier of Article 83(4): up to EUR 10 million or 2% of worldwide annual turnover, whichever is higher.

09

Privacy by design principles: the seven foundational principles

The phrase predates the GDPR. Ann Cavoukian, as Information and Privacy Commissioner of Ontario, set out seven foundational principles that many teams still use as a design checklist: proactive not reactive, preventative not remedial; privacy as the default setting; privacy embedded into design; full functionality, positive-sum not zero-sum; end-to-end security across the whole lifecycle; visibility and transparency; and respect for user privacy. They are a framework, not law. The legal duty in the EU and UK is Article 25, and that is what you will be assessed against.

10

GDPR requirements: how they map to the principles

Most specific GDPR requirements are one or more principles made concrete. Read together, this is the outline of a GDPR programme. Not sure the GDPR reaches you at all? Try the GDPR applicability checker.

RequirementArticlePrinciple it serves
Have a lawful basis for each purpose6Lawfulness
Consent that is freely given, specific, informed and as easy to withdraw as to give7Lawfulness, fairness
Extra conditions for special category data9Lawfulness
Tell people what you do with their data13, 14Transparency
Answer rights requests within one month12, 15 to 22Transparency, accuracy
Appoint an EU or UK representative if you have no establishment there27Accountability
Bind processors by contract28Integrity, accountability
Keep a record of processing activities30Accountability
Secure the processing32Integrity and confidentiality
Report personal data breaches within 72 hours where required33, 34Integrity, accountability
Run a DPIA for high-risk processing35Accountability
Designate a DPO where Article 37 requires one37Accountability
Protect data transferred outside the EEA44 to 49All of them, abroad

An overview, not a complete list. Member State law and sector rules add more.

11

Where TryTrustable fits

The principles are judgement calls you make once and then have to evidence for years. The platform holds that evidence, and maps each control across GDPR, UK GDPR and the other frameworks you run so one piece of work counts everywhere. See GDPR for SaaS for the full programme.

PrincipleWhere TryTrustable helps
Lawfulness and transparencyA consent banner that blocks trackers until the visitor chooses, with each notice version recorded; free privacy policy and cookie policy generators
Purpose limitationConsent recorded per purpose, and withdrawals sent to each processor's webhook with every delivery logged
MinimisationThe free cookie scanner shows which trackers fire before consent
Accuracy and storage limitationA rights queue for correction and erasure requests, with deadlines set at receipt
Integrity and confidentialitySecurity controls mapped once across GDPR, ISO 27001 and SOC 2, with evidence from GitHub, AWS and GCP
AccountabilityA tamper-evident consent ledger, evidence ledger, policies, risk register and vendor register, all in one place an auditor can read

Tools that hold the evidence. The decisions about purposes, bases and retention stay with you.

Questions

The things people ask us

What are the 7 principles of GDPR?

Lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. They are in Article 5 of the GDPR and the UK GDPR.

Which GDPR principle covers data retention?

Storage limitation, Article 5(1)(e): keep data in a form that identifies people for no longer than the purpose needs. The GDPR does not set fixed periods; you set and justify them.

What is the difference between privacy by design and privacy by default?

By design means building measures into how you process data so the principles are met. By default means the settings, out of the box, process only what each purpose needs, and do not expose data to an indefinite number of people without the person's action.

Is accountability a GDPR principle?

Yes. Article 5(2) makes the controller responsible for complying with the other principles and able to demonstrate that it does.

What is the fine for breaching the GDPR principles?

Infringements of Article 5 fall under Article 83(5): up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher. Our GDPR fine calculator shows the ceiling for your turnover.

Are the UK GDPR principles different?

No. The UK GDPR keeps the same seven principles in Article 5. The Data (Use and Access) Act 2025 changed other parts of UK law, such as lawful bases and children's online services.

Book a walkthrough

Turn the seven principles into evidence you can show.

Thirty minutes on your consent records, processing register and the GDPR and UK GDPR controls you already run.