GDPR Article 5 Principles of Processing
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This content specifically addresses the foundational principles of personal data processing under GDPR Article 5, which encompasses multiple related but distinct principles that warrant a dedicated topic for comprehensive coverage of this critical regulatory framework.
Overview
10 sources · Jul 23, 2026Legal Framework
Article 5 GDPR establishes seven foundational principles governing all personal data processing: lawfulness, fairness, and transparency (Article 5(1)(a)); purpose limitation (Article 5(1)(b)); data minimisation (Article 5(1)(c)); accuracy (Article 5(1)(d)); storage limitation (Article 5(1)(e)); integrity and confidentiality (Article 5(1)(f)); and accountability (Article 5(2)). These principles operate as the substantive yardstick against which every processing activity is measured, irrespective of the lawful basis relied upon under Article 6. Recital 45 reinforces that where processing is grounded in legal obligation or public interest tasks, the underlying Union or Member State law must provide an adequate basis, though it need not legislate each individual processing operation. Recital 85 underscores the material consequences of failing to uphold these principles, particularly the integrity and confidentiality requirement, noting that breaches can produce physical, material, or non-material damage including identity theft, financial loss, reputational harm, and loss of confidentiality. The accountability principle in Article 5(2) is distinctively demanding: controllers must not only comply but demonstrate compliance, shifting the evidential burden onto the organisation itself.
Key Developments
The Court of Justice's reasoning in Minister voor Immigratie v. M (2014) illustrates the practical interdependence between Article 5 principles and data subject rights. The Court established that the right of access functions as a prerequisite for exercising rectification and erasure, and that compliance requires providing data in an intelligible form sufficient for the individual to verify accuracy and lawfulness of processing. This directly operationalises the accuracy and transparency principles of Article 5(1)(a) and (d). The Rechtbank Midden-Nederland decision (case 20/268) further refined the boundaries of accuracy: legal analyses and juridical assessments derived from underlying factual data are not themselves personal data subject to rectification, even when contained in a file concerning an individual. This distinguishes between factual data, which must be accurate under Article 5(1)(d), and interpretive legal conclusions drawn from those facts. The EDPB Guidelines 4/2019 on Article 25 reinforce that data protection by design and by default is the operational mechanism through which Article 5 principles are embedded into processing systems from the outset, requiring controllers to configure defaults that minimise data collection and restrict access to what is strictly necessary.
Practical Guidance
- Map every processing activity to specific Article 5 sub-principles: Document how each processing operation satisfies lawfulness, purpose limitation, minimisation, accuracy, storage limitation, and security, with the accountability record maintained under Article 5(2) as living evidence rather than a one-time exercise.
- Implement purpose specification at collection: Record the explicit, specified purpose at the point of data collection and establish technical controls preventing further processing incompatible with that purpose, consistent with Article 5(1)(b).
- Configure systems to enforce minimisation by default: Apply Article 25 data protection by design principles to ensure that default settings collect only necessary data fields, restrict access permissions to the minimum required, and automatically trigger retention-deletion schedules aligned with Article 5(1)(e).
- Distinguish factual data from legal analysis in access requests: When responding to Article 15 access requests, provide underlying factual personal data in intelligible form as required by Minister v. M, but recognise that juridical interpretations derived from those facts fall outside the rectification scope per Rechtbank Midden-Nederland 20/268.
- Establish breach response protocols tied to integrity obligations: Given Recital 85's enumeration of potential harms, ensure that security measures under Article 5(1)(f) are complemented by rapid breach detection and notification procedures that address both technical containment and individual harm mitigation.