Accountability
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Principle of demonstrating GDPR compliance
Overview
24 sources · Jul 23, 2026Legal Framework
Accountability under the GDPR is anchored in Article 5(2), which requires controllers to be responsible for and demonstrate compliance with the data protection principles set out in Article 5(1). This is operationalised through Article 24, which obliges controllers to implement appropriate technical and organisational measures both to ensure and to demonstrate that processing complies with the Regulation. Article 25 extends this into design and default obligations, while Article 28 imposes parallel accountability requirements on processor relationships.
The dual function of Article 24 is critical: controllers must not only comply but also maintain the evidence to prove compliance. As the Regulation states:
"the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation"
— GDPR Art. 24(1)
Article 24(3) further provides that adherence to approved codes of conduct or certification mechanisms may serve as an element to demonstrate compliance, giving controllers concrete tools to discharge their accountability burden.
Key Developments
Dutch courts have begun applying the accountability principle in enforcement actions. In a recent administrative fine case, the Rechtbank confirmed that the controller bears an affirmative duty to account for its processing decisions:
"De verwerkingsverantwoordelijke is verantwoordelijk voor de naleving van deze beginselen en heeft ten aanzien van die naleving een verantwoordingsplicht."
— Rechtbank, AVG Handhaving ¶8.3
In a separate case concerning a data subject access request, the court accepted the controller's accountability documentation where it had adequately motivated the purpose basis for retaining personal data after termination of employment, finding the explanation sufficient to discharge the verantwoordingsplicht (Rechtbank ¶11).
The EDPB has reinforced that accountability is not confined to processing principles but permeates the entire regulatory architecture. In the context of consent:
"the burden of proof in Article 7(4) is on the controller. 25 This specific rule reflects the general principle of accountability, which runs throughout the GDPR."
— EDPB Guidelines 05/2020 §36
The EDPB has also linked accountability to breach response preparedness, recommending that controllers maintain pre-established breach handling documentation to meet their obligations without undue delay (EDPB Guidelines 01/2021 §13).
Status of the Debate
The accountability principle itself is well-established at the level of the legal text. However, its operational boundaries remain contested in court. The core tension concerns the evidentiary threshold: what quantum and quality of documentation suffices to "demonstrate" compliance under Article 24(1). Courts have diverged on whether a controller's ex post reasoning can cure a documentation deficit, or whether contemporaneous records are required. The Schrems II ruling and subsequent CJEU case law have intensified scrutiny of accountability in cross-border transfer contexts, where demonstrating compliance involves complex assessments of third-country safeguards. No definitive CJEU ruling has yet set a uniform evidentiary standard for the verantwoordingsplicht. A preliminary reference clarifying whether retroactive justification can satisfy Article 24(1) would resolve the principal open question.
Practical Guidance
- Maintain contemporaneous documentation: Article 24(1) requires the ability to demonstrate compliance at the time of processing, not merely after the fact. Record processing decisions, lawful basis assessments, and necessity analyses as they are made.
- Implement data protection policies proportionate to processing scale: Article 24(2) requires formal policies where proportionate — for high-volume or high-risk processing, written policies are not optional.
- Leverage certification and codes of conduct: Article 24(3) explicitly permits these as compliance evidence. Pursuing certification under Article 42 provides a defensible posture in enforcement proceedings.
- Embed accountability in processor contracts: Article 28(3) requires binding contractual terms specifying processing scope, instructions, and security obligations — these contracts are your primary evidence of processor oversight.
- Pre-establish breach response procedures: The EDPB recommends advance preparation of breach handling documentation so that accountability obligations are met without undue delay when incidents occur.