Skip to content
Topic Contested in court

GDPR Article 5 Principles of Processing

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This content specifically addresses the foundational principles of personal data processing under GDPR Article 5, which encompasses multiple related but distinct principles that warrant a dedicated topic for comprehensive coverage of this critical regulatory framework.

50 linked items 1 Laws2 Case Law22 Guidance25 News

Overview

10 sources · Jul 23, 2026

Legal Framework

Article 5 GDPR establishes seven foundational principles governing all personal data processing: lawfulness, fairness, and transparency (Article 5(1)(a)); purpose limitation (Article 5(1)(b)); data minimisation (Article 5(1)(c)); accuracy (Article 5(1)(d)); storage limitation (Article 5(1)(e)); integrity and confidentiality (Article 5(1)(f)); and accountability (Article 5(2)). These principles operate as the substantive yardstick against which every processing activity is measured, irrespective of the lawful basis relied upon under Article 6. Recital 45 reinforces that where processing is grounded in legal obligation or public interest tasks, the underlying Union or Member State law must provide an adequate basis, though it need not legislate each individual processing operation. Recital 85 underscores the material consequences of failing to uphold these principles, particularly the integrity and confidentiality requirement, noting that breaches can produce physical, material, or non-material damage including identity theft, financial loss, reputational harm, and loss of confidentiality. The accountability principle in Article 5(2) is distinctively demanding: controllers must not only comply but demonstrate compliance, shifting the evidential burden onto the organisation itself.

Key Developments

The Court of Justice's reasoning in Minister voor Immigratie v. M (2014) illustrates the practical interdependence between Article 5 principles and data subject rights. The Court established that the right of access functions as a prerequisite for exercising rectification and erasure, and that compliance requires providing data in an intelligible form sufficient for the individual to verify accuracy and lawfulness of processing. This directly operationalises the accuracy and transparency principles of Article 5(1)(a) and (d). The Rechtbank Midden-Nederland decision (case 20/268) further refined the boundaries of accuracy: legal analyses and juridical assessments derived from underlying factual data are not themselves personal data subject to rectification, even when contained in a file concerning an individual. This distinguishes between factual data, which must be accurate under Article 5(1)(d), and interpretive legal conclusions drawn from those facts. The EDPB Guidelines 4/2019 on Article 25 reinforce that data protection by design and by default is the operational mechanism through which Article 5 principles are embedded into processing systems from the outset, requiring controllers to configure defaults that minimise data collection and restrict access to what is strictly necessary.

Practical Guidance

  • Map every processing activity to specific Article 5 sub-principles: Document how each processing operation satisfies lawfulness, purpose limitation, minimisation, accuracy, storage limitation, and security, with the accountability record maintained under Article 5(2) as living evidence rather than a one-time exercise.
  • Implement purpose specification at collection: Record the explicit, specified purpose at the point of data collection and establish technical controls preventing further processing incompatible with that purpose, consistent with Article 5(1)(b).
  • Configure systems to enforce minimisation by default: Apply Article 25 data protection by design principles to ensure that default settings collect only necessary data fields, restrict access permissions to the minimum required, and automatically trigger retention-deletion schedules aligned with Article 5(1)(e).
  • Distinguish factual data from legal analysis in access requests: When responding to Article 15 access requests, provide underlying factual personal data in intelligible form as required by Minister v. M, but recognise that juridical interpretations derived from those facts fall outside the rectification scope per Rechtbank Midden-Nederland 20/268.
  • Establish breach response protocols tied to integrity obligations: Given Recital 85's enumeration of potential harms, ensure that security measures under Article 5(1)(f) are complemented by rapid breach detection and notification procedures that address both technical containment and individual harm mitigation.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 1
Art. 5(1)(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further proc… GDPR Art. 5(1)(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processe… GDPR Art. 6(3) The basis for the processing referred to in point (c) and (e) of paragraph 1 shall be laid down by: GDPR Art. 47(2)(d) the application of the general data protection principles, in particular purpose limitation, data minimisation, limited storage periods, data quality,… GDPR rec 85 Recital 85 — personal data breach notification requirements GDPR Apr 2016
Case Law 2
CJEU MINISTER VOOR IMMIGRATIE V. M, 17.7.2014 (“Minister v. M”) CJEU Jul 2014 CJEU Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy CJEU Sep 2017
Guidance 22
guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on deceptive design patterns in social media platform interfaces how to recognise Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them EDPB Feb 2023 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 guidelines on the interplay of the second payment services directive and the gdpr Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR EDPB Dec 2020 guidelines on the criteria of the right to be forgotten in the search engines cases under th Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) EDPB Jul 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 guidelines on processing of personal data through video devices Guidelines 3/2019 on processing of personal data through video devices EDPB Jan 2020 guidelines on processing personal data in the context of connected vehicles and mobility rel Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Jan 2020 guidelines on codes of conduct and monitoring bodies Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 EDPB Jun 2019 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 guidelines on the use of facial recognition technology in the area of law enforcement Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement EDPB May 2023 Show 2 more →
News 25
European Data Protection Board EDPB and EDPS support streamlining AI Act implementation but call for stronger safeguards to protect fundamental rights European Data Protection Board Jan 2026 Electronic Frontier Foundation “Free” Surveillance Tech Still Comes at a High and Dangerous Cost Electronic Frontier Foundation Feb 2026 European Digital Rights EDRi launches new resource to document abuses and support a full ban on spyware in Europe European Digital Rights Jan 2026 Electronic Frontier Foundation EFF Statement on ICE and CBP Violence Electronic Frontier Foundation Jan 2026 Electronic Frontier Foundation New Report Helps Journalists Dig Deeper Into Police Surveillance Technology Electronic Frontier Foundation Feb 2026 Electronic Frontier Foundation Protecting Our Right to Sue Federal Agents Who Violate the Constitution Electronic Frontier Foundation Feb 2026 Access Now MTN Group must answer for dangerous bounty SMS campaign in the Republic of Congo Access Now Dec 2025 European Digital Rights EU adopts Digital Trade Agreement with Singapore despite warnings: a setback for digital rights and democratic oversight European Digital Rights Nov 2025 Access Now #KeepItOn: Iran plunged into digital darkness, concealing human rights abuses Access Now Jan 2026 NL EU Court Expert CJEU clarifies GDPR principles of purpose limitation and storage limitation NL EU Court Expert Oct 2022 Future of Privacy Forum What Happened to the Risk-Based Approach to Data Transfers? Future of Privacy Forum Sep 2022 NL EU Court Expert A-G: rechtmatig verzamelde en opgeslagen persoonsgegevens mogen onder voorwaarden tijdelijk in een extra interne databank worden bewaard NL EU Court Expert Apr 2022 NL Hogan Lovells UK data protection reform: How the UK's GDPR may change Hogan Lovells Sep 2022 Hunton Andrews Kurth ICO Publishes Draft Employee Monitoring Guidance for Consultation Hunton Andrews Kurth Oct 2022 noyb - European Center for Digital Rights Statement on European Data Protection Day noyb - European Center for Digital Rights Jan 2021 noyb - European Center for Digital Rights German DPA declares data trading between credit agency and address trader illegal noyb - European Center for Digital Rights Feb 2024 IAPP AEPD issues guidance for anonymization IAPP Feb 2023 Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 Fair Trials Europol told to hand over personal data to Dutch activist Fair Trials Sep 2022 Hunton Andrews Kurth CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR Hunton Andrews Kurth Aug 2022 Show 5 more →