Skip to content
Topic Contested in court

GDPR Article 5 Principles of Processing

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This content specifically addresses the foundational principles of personal data processing under GDPR Article 5, which encompasses multiple related but distinct principles that warrant a dedicated topic for comprehensive coverage of this critical regulatory framework.

59 linked items 2 Laws2 Case Law22 Guidance4 Enforcement29 News

Overview

10 sources · Jul 23, 2026

Legal Framework

Article 5 GDPR establishes seven foundational principles governing all personal data processing: lawfulness, fairness, and transparency (Article 5(1)(a)); purpose limitation (Article 5(1)(b)); data minimisation (Article 5(1)(c)); accuracy (Article 5(1)(d)); storage limitation (Article 5(1)(e)); integrity and confidentiality (Article 5(1)(f)); and accountability (Article 5(2)). These principles operate as the substantive yardstick against which every processing activity is measured, irrespective of the lawful basis relied upon under Article 6. Recital 45 reinforces that where processing is grounded in legal obligation or public interest tasks, the underlying Union or Member State law must provide an adequate basis, though it need not legislate each individual processing operation. Recital 85 underscores the material consequences of failing to uphold these principles, particularly the integrity and confidentiality requirement, noting that breaches can produce physical, material, or non-material damage including identity theft, financial loss, reputational harm, and loss of confidentiality. The accountability principle in Article 5(2) is distinctively demanding: controllers must not only comply but demonstrate compliance, shifting the evidential burden onto the organisation itself.

Key Developments

The Court of Justice's reasoning in Minister voor Immigratie v. M (2014) illustrates the practical interdependence between Article 5 principles and data subject rights. The Court established that the right of access functions as a prerequisite for exercising rectification and erasure, and that compliance requires providing data in an intelligible form sufficient for the individual to verify accuracy and lawfulness of processing. This directly operationalises the accuracy and transparency principles of Article 5(1)(a) and (d). The Rechtbank Midden-Nederland decision (case 20/268) further refined the boundaries of accuracy: legal analyses and juridical assessments derived from underlying factual data are not themselves personal data subject to rectification, even when contained in a file concerning an individual. This distinguishes between factual data, which must be accurate under Article 5(1)(d), and interpretive legal conclusions drawn from those facts. The EDPB Guidelines 4/2019 on Article 25 reinforce that data protection by design and by default is the operational mechanism through which Article 5 principles are embedded into processing systems from the outset, requiring controllers to configure defaults that minimise data collection and restrict access to what is strictly necessary.

Practical Guidance

  • Map every processing activity to specific Article 5 sub-principles: Document how each processing operation satisfies lawfulness, purpose limitation, minimisation, accuracy, storage limitation, and security, with the accountability record maintained under Article 5(2) as living evidence rather than a one-time exercise.
  • Implement purpose specification at collection: Record the explicit, specified purpose at the point of data collection and establish technical controls preventing further processing incompatible with that purpose, consistent with Article 5(1)(b).
  • Configure systems to enforce minimisation by default: Apply Article 25 data protection by design principles to ensure that default settings collect only necessary data fields, restrict access permissions to the minimum required, and automatically trigger retention-deletion schedules aligned with Article 5(1)(e).
  • Distinguish factual data from legal analysis in access requests: When responding to Article 15 access requests, provide underlying factual personal data in intelligible form as required by Minister v. M, but recognise that juridical interpretations derived from those facts fall outside the rectification scope per Rechtbank Midden-Nederland 20/268.
  • Establish breach response protocols tied to integrity obligations: Given Recital 85's enumeration of potential harms, ensure that security measures under Article 5(1)(f) are complemented by rapid breach detection and notification procedures that address both technical containment and individual harm mitigation.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Guidance EDPB Oct 2020 Data protection principles implementation
why this is here
The data protection principles are in Article 5 ( henceforth “the principles”)

The document explicitly refers to Article 5 principles as the basis for measures under Article 25, connecting directly to this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Article 5 principles
why this is here
The general principles in GDPR (Article 5), should always be carefully considered when dealing with video surveillance.

The document explicitly states that Article 5 principles are fundamental to video surveillance and elaborates on purpose limitation, data minimisation, and storage limitation.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 03/2022 Deceptive design patterns in social media platform interfaces: how to recognise and avoid them Guidelines ·EDPB Guidance EDPB Feb 2023 Applicable principles of processing
why this is here
Regarding the data protection compliance of user interfaces of online applications within the social media sector, the data protection principles applicable are set out within Article 5 GDPR.

The document directly engages with Article 5 GDPR principles, including fairness, transparency, purpose limitation, and data minimization.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy Principles (Purpose Limitation): The objective of the processing of personal data is inextricably linked to the task of the controller. Consequently, the transfer of the task to… CJEU Case Law CJEU Sep 2017 Purpose limitation principle
why this is here
Article 6(1)(b) of Directive 95/46 requires that personal data be collected for specific, explicit and legitimate purposes

Directly addresses the purpose limitation principle, a core principle also under GDPR Article 5(1)(b).

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 1/2019 Codes of Conduct and Monitoring Bodies under Regulation 2016/679 Guidelines on codes of conduct and monitoring bodies Guidelines ·EDPB Guidance EDPB Jun 2019 codes operationalizing GDPR principles
why this is here
give operational meaning to the principles of data protection set out in European and National law

The document references the principles of data protection, but its focus is on codes of conduct rather than the principles themselves.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 10/2020 restrictions under Article 23 GDPR Guidelines ·EDPB Guidance EDPB Oct 2021 principles in relation to restrictions
why this is here
Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22 GDPR

The document mentions Article 5 principles in the context of restrictions, indicating their relevance to the derogation.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 1/2018 certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation Guidelines ·EDPB Guidance EDPB Jun 2019 Article 5 principles as criteria basis
why this is here
the principles of data processing pursuant to Article 5;

The document refers to Article 5 principles as a general category for certification criteria, but does not analyze them in depth.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 07/2022 certification as a tool for transfers Guidelines on certification and identifying certification criteria Guidelines ·EDPB Guidance EDPB Feb 2023 general principles as precondition
why this is here
Compliance with the principles in Article 5 GDPR

The document refers to Article 5 principles as a general precondition for transfers, but does not analyze them in depth.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 8/2020 targeting of social media users Guidelines ·EDPB Guidance EDPB Apr 2021 Principles application
why this is here
Targeting of social media users may involve uses of personal data that go against or beyond individuals’ reasonable expectations and thereby infringes applicable data protection principles and rules.

Mentions principles but not a detailed analysis.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 05/2022 use of facial recognition technology in the area of law enforcement Guidelines ·EDPB Guidance EDPB May 2023 lawfulness, necessity, proportionality
why this is here
The data has to be processed in a way that ensures the applicability and effectiveness of the EU data protection rules and principles.

References EU data protection principles, which include Article 5 GDPR principles, though in LED context.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 05/2020 consent under Regulation 2016/679 Guidelines on consent Guidelines ·EDPB Guidance EDPB May 2020 fairness and necessity principles
why this is here
obtaining consent also does not negate or in any way diminish the controller’s obligations to observe the principles of processing enshrined in the GDPR, especially Article 5

References Article 5 principles but only in passing; main focus is consent.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Guidance EDPB Jul 2021 Reference to Article 5 principles
why this is here
the controller shall be responsible for the compliance with the principles set out in Article 5(1) GDPR

Article 5 principles are referenced only to establish accountability, not discussed as principles themselves.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 06/2020 interplay of the Second Payment Services Directive and the GDPR Guidelines on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Guidelines ·EDPB Guidance EDPB Dec 2020 Mention of Article 5 principles
why this is here
including the principles of data protection set out in Article 5 of the GDPR

The document mentions Article 5 principles but does not analyze them in detail.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Guidance EDPB Apr 2023 Transparency principle in access responses
why this is here
The communication of data and other information about the processing must be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language.

The document touches on the transparency principle as part of access provisions, but it is not about Article 5 generally.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

CJEU clarifies GDPR principles of purpose limitation and storage limitation ⇄ The purpose limitation principle does not preclude a controller from capturing and storing in a test database established for testing and error correction purposes personal data… News NL EU Court Expert Oct 2022 purpose limitation and storage limitation
why this is here
Het EU-Hof stelt vast dat persoonsgegevens volgens artikel 5, lid 1, onder b van de AVG, waarin het beginsel van doelbinding is vastgelegd

This is the core topic; the CJEU interprets Article 5(1)(b) and (e) principles, which are the primary legal basis of the judgment.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

What Happened to the Risk-Based Approach to Data Transfers? The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute… News Future of Privacy Forum Sep 2022 Art 5(2) vs Art 24 accountability
why this is here
The EDPB is trying to rewrite the GDPR by applying the accountability principle of Article 5(2) GDPR (which does not include the RBA) rather than the accountability principle of Article 24

The document extensively analyzes Article 5(2) and its relationship with the RBA and Article 24, central to interpreting Article 5 principles.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

UK data protection reform: How the UK's GDPR may change > The current version of the Bill seeks to maintain the majority of key principles that underpin the UK data protection law framework, while at the same time modifying certain key… News Hogan Lovells Sep 2022 amends key principles
why this is here
seeks to maintain the majority of key principles that underpin the UK data protection law framework

The article discusses modifications to the UK GDPR, which includes the principles of processing under Article 5, and specifically mentions lawful grounds for processing.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

ICO Publishes Draft Employee Monitoring Guidance for Consultation > On October 14, 2022, the Federal Trade Commission announced it is extending the deadline by one month to submit comments on its Advanced Notice of Proposed Rulemaking on… News Hunton Andrews Kurth Oct 2022 Compliance with GDPR principles
why this is here
complying with the principles of the UK GDPR

The principles are referenced generically, not specifically discussed as Article 5 principles; the focus is on practical compliance.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 22 Guidance · all 29 News