Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Article 5 (Principles)
Resources
🇫🇷 FR 🇬🇧 EN 🇳🇱 NL
EU Reference Binding Legal Text (Art. 5)

Article 5 GDPR: Cardinal Processing Principles & Accountability

Official EU Regulation (EU) 2016/679 legal analysis

⚡ In 30 seconds:

Article 5(1) GDPR lays down six mandatory principles: processing must be lawful, pursue explicit purposes, limit data to what is necessary, ensure accuracy, restrict storage periods, and guarantee security. Article 5(2) establishes the core principle of Accountability.

The 6 Cardinal Processing Principles (Art. 5.1)

Article 5(1) of the GDPR constitutes the cornerstone of European data protection regulation. Any personal data processing must continuously comply with these substantive requirements:

  • Lawfulness, fairness and transparency (Art. 5.1.a): Processed lawfully, fairly and in a transparent manner in relation to the data subject.
  • Purpose limitation (Art. 5.1.b): Collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.
  • Data minimisation (Art. 5.1.c): Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
  • Accuracy (Art. 5.1.d): Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that inaccurate data are erased or rectified without delay.
  • Storage limitation (Art. 5.1.e): Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
  • Integrity and confidentiality (Art. 5.1.f): Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

The Accountability Principle & Evidentiary Burden (Art. 5.2 & 24)

Article 5(2) enshrines the foundational principle of Accountability: the controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1.

Accountability is an ongoing proactive obligation: documented policies, data protection impact assessments (DPIAs), records of processing activities, and technical and organisational security safeguards.

Verified Official Sources

⚖️ Binding EU Legal Act
Regulation (EU) 2016/679 (Official Journal of the European Union, EUR-Lex EN)

CELEX: 32016R0679 · Official English consolidated version

← ← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-23 Last modified: 2026-08-23

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice