Accountability
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Principle of demonstrating GDPR compliance
Overview
24 sources · Jul 23, 2026Legal Framework
Accountability under the GDPR is anchored in Article 5(2), which requires controllers to be responsible for and demonstrate compliance with the data protection principles set out in Article 5(1). This is operationalised through Article 24, which obliges controllers to implement appropriate technical and organisational measures both to ensure and to demonstrate that processing complies with the Regulation. Article 25 extends this into design and default obligations, while Article 28 imposes parallel accountability requirements on processor relationships.
The dual function of Article 24 is critical: controllers must not only comply but also maintain the evidence to prove compliance. As the Regulation states:
"the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation"
— GDPR Art. 24(1)
Article 24(3) further provides that adherence to approved codes of conduct or certification mechanisms may serve as an element to demonstrate compliance, giving controllers concrete tools to discharge their accountability burden.
Key Developments
Dutch courts have begun applying the accountability principle in enforcement actions. In a recent administrative fine case, the Rechtbank confirmed that the controller bears an affirmative duty to account for its processing decisions:
"De verwerkingsverantwoordelijke is verantwoordelijk voor de naleving van deze beginselen en heeft ten aanzien van die naleving een verantwoordingsplicht."
— Rechtbank, AVG Handhaving ¶8.3
In a separate case concerning a data subject access request, the court accepted the controller's accountability documentation where it had adequately motivated the purpose basis for retaining personal data after termination of employment, finding the explanation sufficient to discharge the verantwoordingsplicht (Rechtbank ¶11).
The EDPB has reinforced that accountability is not confined to processing principles but permeates the entire regulatory architecture. In the context of consent:
"the burden of proof in Article 7(4) is on the controller. 25 This specific rule reflects the general principle of accountability, which runs throughout the GDPR."
— EDPB Guidelines 05/2020 §36
The EDPB has also linked accountability to breach response preparedness, recommending that controllers maintain pre-established breach handling documentation to meet their obligations without undue delay (EDPB Guidelines 01/2021 §13).
Status of the Debate
The accountability principle itself is well-established at the level of the legal text. However, its operational boundaries remain contested in court. The core tension concerns the evidentiary threshold: what quantum and quality of documentation suffices to "demonstrate" compliance under Article 24(1). Courts have diverged on whether a controller's ex post reasoning can cure a documentation deficit, or whether contemporaneous records are required. The Schrems II ruling and subsequent CJEU case law have intensified scrutiny of accountability in cross-border transfer contexts, where demonstrating compliance involves complex assessments of third-country safeguards. No definitive CJEU ruling has yet set a uniform evidentiary standard for the verantwoordingsplicht. A preliminary reference clarifying whether retroactive justification can satisfy Article 24(1) would resolve the principal open question.
Practical Guidance
- Maintain contemporaneous documentation: Article 24(1) requires the ability to demonstrate compliance at the time of processing, not merely after the fact. Record processing decisions, lawful basis assessments, and necessity analyses as they are made.
- Implement data protection policies proportionate to processing scale: Article 24(2) requires formal policies where proportionate — for high-volume or high-risk processing, written policies are not optional.
- Leverage certification and codes of conduct: Article 24(3) explicitly permits these as compliance evidence. Pursuing certification under Article 42 provides a defensible posture in enforcement proceedings.
- Embed accountability in processor contracts: Article 28(3) requires binding contractual terms specifying processing scope, instructions, and security obligations — these contracts are your primary evidence of processor oversight.
- Pre-establish breach response procedures: The EDPB recommends advance preparation of breach handling documentation so that accountability obligations are met without undue delay when incidents occur.
why this is here
Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility.
The provision directly imposes the core documentation obligation that underpins the accountability principle, requiring a written record that demonstrates compliance with GDPR obligations.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
The GDPR also introduces the principle of accountability, which places the onus on data controllers to be responsible for, and be able to demonstrate compliance with the Regulation.
The document directly discusses how codes of conduct serve as accountability tools and mechanisms to demonstrate GDPR compliance, a central aspect of the accountability principle.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
explore the rationale for certification as an accountability tool;
The document explicitly frames certification as an accountability tool and discusses how it helps demonstrate compliance under GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the controller shall be responsible for the compliance with the principles set out in Article 5(1) GDPR; and that − the controller shall be able to demonstrate compliance with the principles set out in Article 5(1) GDPR
The document explicitly references Article 5(2) GDPR accountability principle and its implications for controllers.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the accountability principle, as laid down in Article 5(2) GDPR, is still applicable
The document explicitly states that the accountability principle remains applicable even when restrictions are imposed, making it a primary source for this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Accountability can be provided by elements that provide proof of the social media provider’s compliance with the GDPR.
The document explicitly elaborates on how user interfaces and user journeys can demonstrate accountability under Article 5(2) GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the controller must verify the appropriateness of the measures for the particular processing in question.
The requirement to verify appropriateness relates to demonstrating compliance, a core accountability aspect.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the importer to have assessed the rules and practices of the third country where it operates and whether they prevent the importer from complying with its commitments under the certification
The certification criteria require the importer to document its assessment of third-country laws and practices, which aligns with demonstrating compliance.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Controllers and processors are therefore encouraged to plan in advance and put in place processes to be able to detect and promptly contain a breach
The document encourages proactive planning and processes, which are part of demonstrating accountability in breach preparedness.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the present guidelines offer guidance concerning the targeting of social media users, in particular as regards the responsibilities of targeters and social media providers.
Discusses responsibilities of actors, which links to accountability, but not the main focus.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.
Paragraph 3 mentions demonstrating compliance only through a certification mechanism, which is a narrow link to the broader accountability principle; it does not address the general record-keeping or demonstration duties of Article 5(2).
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
in accordance with the accountability principle
The document mentions the accountability principle in the context of fraud prevention but does not develop the concept further.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the LSA shall “ communicate the relevant information on the mat ter ”, i.e. the case in
The duty to exchange relevant information under Article 60(1) relates to the accountability principle but only indirectly.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
PETs can help you demonstrate a ‘data protection by design and by default’ approach to your processing.
The document notes PETs help demonstrate a by-design approach, which is a component of accountability under Article 5(2), but it does not focus on record-keeping or broader accountability obligations.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 23 Laws · all 145 Guidance · all 74 Case Law · all 219 Enforcement · all 67 Literature · all 44 News