Accuracy
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Principle that personal data must be accurate and up to date
Overview
21 sources · Jul 23, 2026Legal Framework
Article 5(1)(d) GDPR establishes the accuracy principle, requiring that personal data be accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that data which are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay. This principle is operationalized through Article 16 GDPR, which grants data subjects the right to obtain from the controller rectification of inaccurate personal data without undue delay. Article 16 also provides the right to have incomplete personal data completed, including by means of a supplementary statement, taking into account the purposes of processing.
The accuracy principle does not impose an absolute guarantee of factual correctness. Rather, it requires proportionate measures appropriate to the processing context. For processing under archiving, scientific research, or statistical purposes, Recital 156 indicates that appropriate safeguards—including data minimization—must be applied, which indirectly supports accuracy by limiting the scope of data processed.
Key Developments
Dutch administrative case law has drawn a critical boundary on the scope of Article 16. The Afdeling bestuursrechtspraak has consistently held that the rectification right is not intended to alter or remove impressions, opinions, research findings, or conclusions with which the data subject disagrees (e.g., ECLI:NL:RVS:2024:243). This means a medical professional's assessment in a patient file, even if contested, generally falls outside the rectification mechanism unless it contains objectively demonstrable factual errors.
The CJEU's ruling in Minister voor Immigratie v. M (17 July 2014) established that the right of access under Article 15 serves as a prerequisite for exercising rectification rights. The controller satisfies the access requirement by providing a full summary of the data in an intelligible form that allows the data subject to verify accuracy—a literal copy of every document is not required.
The Rechtbank Den Haag (C/09/608204 / HA RK 21-96) addressed rectification requests in the context of fraud registers, clarifying that proceedings under Article 35 UAVG are limited to granting or denying requests under Articles 15–22 GDPR. Claims for damages or financial compensation fall outside that procedural scope and must be pursued through separate civil action.
Enforcement actions confirm that accuracy failures carry financial consequences. The Spanish DPA fined Vodafone España €5,000 after a customer was wrongfully charged due to incorrect data handling, and the Croatian DPA (AZOP) imposed a €20,000 fine on a telecommunications company following a complaint about inaccurate personal data processing.
Practical Guidance
Distinguish factual errors from contested opinions. Before processing a rectification request, assess whether the challenged data constitutes an objectively verifiable fact or a professional judgment. Article 16 does not require controllers to amend subjective assessments, research conclusions, or interpretive findings that the data subject simply disputes.
Ensure access mechanisms enable accuracy verification. Provide data subjects with a comprehensive, intelligible summary of their processed data so they can identify potential inaccuracies. This satisfies the access prerequisite identified in Minister v. M and facilitates efficient rectification handling.
Establish internal rectification workflows with defined timelines. Article 16 requires rectification "without undue delay." Implement procedures that triage incoming requests, verify factual claims, and execute corrections or supplementary statements within a documented, reasonable period.
Maintain accuracy in fraud and risk registers with particular care. Registrations in incident registers, FSV entries, or similar databases must be factually substantiated. Courts scrutinize whether recorded inaccuracies were deliberate or negligent, and wrongful registrations can trigger both rectification obligations and separate liability claims.
Account for sector-specific accuracy obligations. Police data, insurance records, and financial sector registrations each carry additional accuracy requirements beyond the GDPR baseline. Verify that processing in these contexts meets both the general accuracy standard and any applicable sectoral rules.