Accuracy
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Principle that personal data must be accurate and up to date
Overview
20 sources · Sep 25, 2026Legal Framework
The accuracy principle in EU data protection law is primarily operationalised through Article 16 GDPR, which grants data subjects the right to obtain rectification of inaccurate personal data without undue delay. The provision also addresses incompleteness, allowing data subjects to have incomplete data completed, including by supplementary statement. The CJEU has consistently reaffirmed this formulation across multiple rulings, treating Article 16 as the operative mechanism through which accuracy is enforced at the individual level.
"The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her."
— GDPR Art. 16
Beyond the GDPR itself, the accuracy principle extends into adjacent regulatory regimes. NIS2 Recital 51 explicitly anchors data accuracy as a Union-wide data protection principle applicable even when innovative technologies, including artificial intelligence, are deployed for cybersecurity purposes. This signals that accuracy obligations are not confined to traditional processing contexts but follow personal data wherever it flows across regulatory domains.
Key Developments
The CJEU has established a clear structural relationship between the right of access (Article 15) and the right to rectification (Article 16). In Österreichische Datenschutzbehörde v CRIF, the Court explained that access functions as a prerequisite enabling data subjects to exercise downstream rights including rectification:
This access-to-rectification pipeline was reaffirmed in CK v Magistrat der Stadt Wien and Proceedings brought by J.M., cementing the principle that controllers cannot meaningfully comply with rectification obligations without first providing adequate access.
At the enforcement level, DPAs are actively scrutinising accuracy in credit reporting contexts. The Italian Garante sanctioned Experian Italia for incomplete access responses that impaired data subjects' ability to identify and correct inaccurate entries. The Greek HDPA ordered TEIRESIAS S.A. to ensure data accuracy under Article 5(1)(d) GDPR, directly linking the foundational accuracy principle to operational rectification duties. The EDPB's 2024 Schengen Information System supervision report further demonstrates that rectification requests are tracked as a measurable compliance metric across Member States.
Status of the Debate
The accuracy principle is contested in court, with boundaries actively litigated. While the CJEU has settled the structural relationship between access and rectification, the substantive question of what constitutes "inaccurate" personal data — particularly in contexts involving predictive analytics, credit scoring, and automated profiling — remains unresolved. The CRIF and Österreichische Post line of cases addresses procedural gateways but does not fully delineate the threshold at which data becomes "inaccurate" for Article 16 purposes. Divergent national approaches to credit data accuracy, as seen in the Italian and Greek enforcement actions, suggest that the substantive contours of the accuracy obligation will require further CJEU clarification — particularly whether "accuracy" encompasses contextual or temporal accuracy beyond factual correctness.
Practical Guidance
Treat access requests as rectification triggers: Since the CJEU has established that access is a necessary precondition for exercising rectification rights, ensure Article 15 responses are sufficiently detailed to allow data subjects to identify inaccuracies. Incomplete access responses, as the Experian Italia sanction demonstrates, can themselves constitute a violation.
Implement proactive accuracy verification for high-risk datasets: Credit bureaus, SIS entries, and similar databases should have systematic accuracy checks rather than relying solely on data-subject-initiated rectification. The Greek HDPA's action against TEIRESIAS signals that regulators expect controllers to maintain accuracy ex ante, not merely respond ex post.
Document the rectification workflow end-to-end: The EDPB's SIS supervision framework tracks both requests submitted and cases where data were actually rectified. Controllers should maintain parallel metrics to demonstrate that rectification requests are processed without undue delay and that corrections propagate to all downstream processors.
Account for accuracy in AI and automated processing: NIS2 Recital 51 makes clear that data accuracy principles apply when AI is used even in cybersecurity contexts. Controllers deploying automated decision-making must ensure that training data and outputs satisfy accuracy requirements under both GDPR and sectoral regimes.
Address temporal accuracy proactively: Article 16's requirement to rectify "without undue delay" implies that data which becomes stale or outdated must be updated or erased. Establish data retention schedules and refresh cycles tied to the purposes of processing.
why this is here
the rectification of inaccurate personal data
The provision directly addresses correction of inaccuracies, which supports the accuracy principle but does not set the principle itself.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
to obtain, depending on the circumstances, the rectification, erasure or blocking of his data by the controller
The document links the right of access to the ability to seek rectification, a key aspect of the accuracy principle.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
it also induces the risk of discrimination and false results.
Mentions false results as a risk, implying concern for accuracy of FRT processing.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
it must be assessed whether or not, over the course of time, the personal data have become out-of-date or have not been updated.
The document mentions outdated or inaccurate data as a factor in assessing delisting under Article 17(1)(a), connecting to the accuracy principle.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
to verify the accuracy of the data processed without having to justify their intention
The document mentions accuracy as one of the purposes of the right of access, but does not address the accuracy principle itself.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
restrictions to the principles relating to the processing of personal data as far as the provisions of Article 5 correspond to the obligations provided in Article 12 to 22 GDPR
The document mentions that Article 5 principles, including accuracy, can be restricted, but it does not focus on accuracy itself.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
The Italian DPA has imposed a fine of EUR 10 million on electricity and gas supplier Axpo Italia Spa. The DPA had received numerous complaints from data subjects who complained that, without their knowledge, electricity and gas contracts had been activated in their own names, of which they had only learned after receiving termination letters from the previous supplier or reminders to pay outstanding bills. They also discovered that their personal data provided in the contract (e.g., email address, phone number and utility number) was incorrect or outdated. During its investigation, the DPA found that the controller had been acquiring new electricity and gas supply contracts through a network of approximately 280 vendors without ensuring that the data entered into the database by the vendors actually corresponded to utility users. This resulted in unsolicited contracts that often contained inaccurate and outdated personal data.
The document directly concerns the principle of accuracy (Art. 5(1)(d)) as it describes inaccurate and outdated personal data resulting from the controller's failure to verify data.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
mainly for non-compliance with the rights of rectification and erasure of the data subjects
The case directly concerns failure to comply with rectification and erasure rights, which are core to the accuracy principle's enforcement, though the principle itself is not the main legal basis cited.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 39 Enforcement · all 27 Guidance · all 28 Literature