GDPR

Knowledge Base | GDPR | What are the 7 principles of GDPR?

What are the 7 principles of GDPR?

The seven GDPR principles govern how organisations handle personal data. They are set out in Article 5 and explained in the European Commission’s guidance on personal data processing principles:

  1. Lawfulness, fairness and transparency: Have a valid legal basis, treat people fairly and clearly explain how their data is used.

  2. Purpose limitation: Collect data for defined, legitimate purposes and assess whether any further use is compatible.

  3. Data minimization: Process only the personal data needed for the stated purpose.

  4. Accuracy: Keep information sufficiently accurate and correct or remove inaccurate data when necessary.

  5. Storage limitation: Keep identifiable data only for as long as the purpose requires, subject to applicable legal exceptions.

  6. Integrity and confidentiality: Use appropriate safeguards against unauthorised access, unlawful processing, loss or damage.

  7. Accountability: Take responsibility for following these principles and maintain evidence demonstrating compliance.