Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Accountability & Proactive Responsibility (Art. 5.2 & 24)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 20/54 Part 2 — Core Principles Intermediate Reviewed 2026-08-23

Accountability & Proactive Responsibility (Art. 5.2 & 24)

Accountability compels controllers to implement active compliance safeguards and maintain continuous documented evidence capable of proving compliance at all times.

Open in interactive reader
⚖️ Keystone of the GDPR 📋 Demonstrable Compliance (Art. 5.2)

Accountability: Proactive Responsibility (Art. 5.2 & 24)

⚡ In 30 seconds

Under Article 5(2), the controller is responsible for, and must be able to demonstrate compliance with, all data protection principles ('accountability'). Coupled with Article 24, accountability obliges organisations to proactively deploy technical and organisational measures, review them regularly, and preserve documentary proof.

Accountability Pillar Required Documentary Evidence
1. Cartography & Records Article 30 Record of Processing Activities; data flow schemas; vendor inventories.
2. Risk Management Data Protection Impact Assessments (Art. 35); Legitimate Interests Assessments (LIA).
3. Internal Governance Information Security Policies (ISP); access management matrices; staff training logs.
4. External Relationships Signed Article 28 DPAs; Standard Contractual Clauses (SCCs) for cross-border transfers.
5. Incident Preparedness Internal data breach register (Art. 33.5); tested 72-hour notification protocol.
⚡ Key Takeaways
  • If an action is not documented, from an enforcement standpoint it did not happen.
  • Supervisory authorities audit documented governance first during inspections.
  • Accountability is dynamic: policies must be tested, audited, and updated regularly.
⚠️ Common Pitfall

Buying off-the-shelf compliance binder templates and leaving them unadapted and unread on a corporate intranet.

🛠️ In Practice

Schedule an annual compliance governance review with executive leadership and your DPO.

⚖️ Official Sources: Art. 5(2), 24 GDPR · Recitals 74, 82 · EDPB Guidelines 4/2019 ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Paradigm shift: from bureaucratic prior declarations to continuous documented proof.
  • Reversal of the evidentiary burden: the controller must demonstrate active compliance.
  • Obligation of documented proportionate means rather than an absolute guarantee.

⚠ Common pitfall: Acting compliantly in daily operations while failing to maintain contemporaneous written records of decisions.

→ Actionable practice: Centralise compliance evidence: register of processing activities, DPIAs, and information security policies.

← Key Stakeholders: Controller vs Processor (Art. 4.7, 4.8) Synthesis: Principles Audit Matrix →