Skip to content
Topic Contested in court

Accountability

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Principle of demonstrating GDPR compliance

575 linked items 23 Laws74 Case Law145 Guidance219 Enforcement44 News

Overview

24 sources · Jul 23, 2026

Legal Framework

Accountability under the GDPR is anchored in Article 5(2), which requires controllers to be responsible for and demonstrate compliance with the data protection principles set out in Article 5(1). This is operationalised through Article 24, which obliges controllers to implement appropriate technical and organisational measures both to ensure and to demonstrate that processing complies with the Regulation. Article 25 extends this into design and default obligations, while Article 28 imposes parallel accountability requirements on processor relationships.

The dual function of Article 24 is critical: controllers must not only comply but also maintain the evidence to prove compliance. As the Regulation states:

"the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation"
— GDPR Art. 24(1)

Article 24(3) further provides that adherence to approved codes of conduct or certification mechanisms may serve as an element to demonstrate compliance, giving controllers concrete tools to discharge their accountability burden.

Key Developments

Dutch courts have begun applying the accountability principle in enforcement actions. In a recent administrative fine case, the Rechtbank confirmed that the controller bears an affirmative duty to account for its processing decisions:

"De verwerkingsverantwoordelijke is verantwoordelijk voor de naleving van deze beginselen en heeft ten aanzien van die naleving een verantwoordingsplicht."
— Rechtbank, AVG Handhaving ¶8.3

In a separate case concerning a data subject access request, the court accepted the controller's accountability documentation where it had adequately motivated the purpose basis for retaining personal data after termination of employment, finding the explanation sufficient to discharge the verantwoordingsplicht (Rechtbank ¶11).

The EDPB has reinforced that accountability is not confined to processing principles but permeates the entire regulatory architecture. In the context of consent:

"the burden of proof in Article 7(4) is on the controller. 25 This specific rule reflects the general principle of accountability, which runs throughout the GDPR."
— EDPB Guidelines 05/2020 §36

The EDPB has also linked accountability to breach response preparedness, recommending that controllers maintain pre-established breach handling documentation to meet their obligations without undue delay (EDPB Guidelines 01/2021 §13).

Status of the Debate

The accountability principle itself is well-established at the level of the legal text. However, its operational boundaries remain contested in court. The core tension concerns the evidentiary threshold: what quantum and quality of documentation suffices to "demonstrate" compliance under Article 24(1). Courts have diverged on whether a controller's ex post reasoning can cure a documentation deficit, or whether contemporaneous records are required. The Schrems II ruling and subsequent CJEU case law have intensified scrutiny of accountability in cross-border transfer contexts, where demonstrating compliance involves complex assessments of third-country safeguards. No definitive CJEU ruling has yet set a uniform evidentiary standard for the verantwoordingsplicht. A preliminary reference clarifying whether retroactive justification can satisfy Article 24(1) would resolve the principal open question.

Practical Guidance

  • Maintain contemporaneous documentation: Article 24(1) requires the ability to demonstrate compliance at the time of processing, not merely after the fact. Record processing decisions, lawful basis assessments, and necessity analyses as they are made.
  • Implement data protection policies proportionate to processing scale: Article 24(2) requires formal policies where proportionate — for high-volume or high-risk processing, written policies are not optional.
  • Leverage certification and codes of conduct: Article 24(3) explicitly permits these as compliance evidence. Pursuing certification under Article 42 provides a defensible posture in enforcement proceedings.
  • Embed accountability in processor contracts: Article 28(3) requires binding contractual terms specifying processing scope, instructions, and security obligations — these contracts are your primary evidence of processor oversight.
  • Pre-establish breach response procedures: The EDPB recommends advance preparation of breach handling documentation so that accountability obligations are met without undue delay when incidents occur.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 30 Records of processing activities Laws GDPR Apr 2016 mandatory record-keeping for compliance
why this is here
Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility.

The provision directly imposes the core documentation obligation that underpins the accountability principle, requiring a written record that demonstrates compliance with GDPR obligations.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 1/2019 Codes of Conduct and Monitoring Bodies under Regulation 2016/679 Guidelines on codes of conduct and monitoring bodies Guidelines ·EDPB Guidance EDPB Jun 2019 accountability principle and compliance demonstration
why this is here
The GDPR also introduces the principle of accountability, which places the onus on data controllers to be responsible for, and be able to demonstrate compliance with the Regulation.

The document directly discusses how codes of conduct serve as accountability tools and mechanisms to demonstrate GDPR compliance, a central aspect of the accountability principle.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 1/2018 certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation Guidelines ·EDPB Guidance EDPB Jun 2019 certification as accountability tool
why this is here
explore the rationale for certification as an accountability tool;

The document explicitly frames certification as an accountability tool and discusses how it helps demonstrate compliance under GDPR.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Guidance EDPB Jul 2021 Demonstrating compliance responsibility
why this is here
the controller shall be responsible for the compliance with the principles set out in Article 5(1) GDPR; and that − the controller shall be able to demonstrate compliance with the principles set out in Article 5(1) GDPR

The document explicitly references Article 5(2) GDPR accountability principle and its implications for controllers.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 10/2020 restrictions under Article 23 GDPR Guidelines ·EDPB Guidance EDPB Oct 2021 Accountability principle applicability
why this is here
the accountability principle, as laid down in Article 5(2) GDPR, is still applicable

The document explicitly states that the accountability principle remains applicable even when restrictions are imposed, making it a primary source for this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 03/2022 Deceptive design patterns in social media platform interfaces: how to recognise and avoid them Guidelines ·EDPB Guidance EDPB Feb 2023 Accountability in interface design
why this is here
Accountability can be provided by elements that provide proof of the social media provider’s compliance with the GDPR.

The document explicitly elaborates on how user interfaces and user journeys can demonstrate accountability under Article 5(2) GDPR.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Guidance EDPB Oct 2020 Demonstrating compliance through measures
why this is here
the controller must verify the appropriateness of the measures for the particular processing in question.

The requirement to verify appropriateness relates to demonstrating compliance, a core accountability aspect.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 07/2022 certification as a tool for transfers Guidelines on certification and identifying certification criteria Guidelines ·EDPB Guidance EDPB Feb 2023 Importer's documented assessment obligations
why this is here
the importer to have assessed the rules and practices of the third country where it operates and whether they prevent the importer from complying with its commitments under the certification

The certification criteria require the importer to document its assessment of third-country laws and practices, which aligns with demonstrating compliance.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Guidance EDPB Apr 2023 demonstrating compliance through breach response
why this is here
Controllers and processors are therefore encouraged to plan in advance and put in place processes to be able to detect and promptly contain a breach

The document encourages proactive planning and processes, which are part of demonstrating accountability in breach preparedness.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 8/2020 targeting of social media users Guidelines ·EDPB Guidance EDPB Apr 2021 Accountability under GDPR
why this is here
the present guidelines offer guidance concerning the targeting of social media users, in particular as regards the responsibilities of targeters and social media providers.

Discusses responsibilities of actors, which links to accountability, but not the main focus.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

art 25 Data protection by design and by default Laws GDPR Apr 2016 Demonstrating compliance via certification
why this is here
An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.

Paragraph 3 mentions demonstrating compliance only through a certification mechanism, which is a narrow link to the broader accountability principle; it does not address the general record-keeping or demonstration duties of Article 5(2).

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 06/2020 interplay of the Second Payment Services Directive and the GDPR Guidelines on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Guidelines ·EDPB Guidance EDPB Dec 2020 Accountability principle mention
why this is here
in accordance with the accountability principle

The document mentions the accountability principle in the context of fraud prevention but does not develop the concept further.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 02/2022 application of Article 60 GDPR Guidelines ·EDPB Guidance EDPB Mar 2022 cooperation as compliance demonstration
why this is here
the LSA shall “ communicate the relevant information on the mat ter ”, i.e. the case in

The duty to exchange relevant information under Article 60(1) relates to the accountability principle but only indirectly.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

ICO: How can Privacy Enhancing Technologies help with data protection compliance? > How can PETs help with data protection compliance? At a glance • PETs can help you demonstrate a ‘data protection by design and by default’ approach to your processing. • PETs… News ICO Nov 2025 demonstrating compliance through PETs
why this is here
PETs can help you demonstrate a ‘data protection by design and by default’ approach to your processing.

The document notes PETs help demonstrate a by-design approach, which is a component of accountability under Article 5(2), but it does not focus on record-keeping or broader accountability obligations.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 23 Laws · all 145 Guidance · all 74 Case Law · all 219 Enforcement · all 67 Literature · all 44 News