Article 5 of the General Data Protection Regulation establishes the foundational principles governing all personal data processing. These principles function as normative anchors—they inform the interpretation of every other GDPR provision and apply horizontally across all processing activities, regardless of the legal basis relied upon. Supervisory authorities and courts consistently treat Article 5 as the primary benchmark for enforcement, making a thorough understanding of its requirements essential for any data protection practitioner.
The controller bears direct responsibility for compliance with each of the six substantive principles and must be able to demonstrate that compliance at any time.
Processing must rely on a valid legal basis under Article 6 (and Article 9 where special category data is involved). No basis, no lawful processing—regardless of intent.
Extends beyond mere legality. Requires that processing causes no unjustified adverse effects and aligns with the reasonable expectations of data subjects. Increasingly invoked in AI and algorithmic decision-making cases, often independently of any transparency breach.
Demands clear, accessible and timely information as required by Articles 12–14. Opaque, deceptive or layered practices that obscure the true nature of processing will constitute a breach of this principle.
Data must be collected for specified, explicit, and legitimate purposes and must not be further processed in a manner incompatible with those purposes. Where further processing is contemplated, Article 6(4) sets out a structured compatibility test.

Personal data must be adequate (sufficient for the stated purpose), relevant, and strictly limited to what is necessary. The necessity test is rigorous—convenience or commercial preference does not justify collection.

Inaccurate financial data can directly harm individuals through incorrect creditworthiness assessments, with serious legal and financial consequences.
Erroneous records in police or criminal justice databases carry the most severe human consequences, including wrongful identification or arrest.
Under Article 22, decisions based solely on automated processing must be grounded in accurate data—inaccuracy can render such decisions unlawful.
Personal data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which it was collected.
Processing must be conducted with appropriate technical and organisational measures to ensure security of personal data. "Appropriate" is assessed on a risk-based basis, directly linked to Article 32.
The controller is responsible for, and must be able to demonstrate compliance with, all six substantive principles. This marks a fundamental shift from formal compliance to demonstrable governance—the burden of proof sits squarely with the controller.
Maintained records of processing activities as the documentary backbone of accountability.
Data Protection Impact Assessments for high-risk processing operations, evidencing proactive risk management.
Policies, procedures and internal standards that embed data protection by design and by default.
Regular staff training and independent audits to demonstrate ongoing, operational compliance.
The following twenty controls span all six substantive principles and the accountability obligation under Article 5(2). Together they form a comprehensive operational compliance framework.
GDPR Article 5: Core Principles of Data Processing