Fiche 20/54
Part 2 — Core Principles
Intermediate
Reviewed 2026-08-23
Accountability & Proactive Responsibility (Art. 5.2 & 24)
Accountability: Proactive Responsibility (Art. 5.2 & 24)
⚡ In 30 seconds
Under Article 5(2), the controller is responsible for, and must be able to demonstrate compliance with, all data protection principles ('accountability'). Coupled with Article 24, accountability obliges organisations to proactively deploy technical and organisational measures, review them regularly, and preserve documentary proof.
| Accountability Pillar | Required Documentary Evidence |
|---|---|
| 1. Cartography & Records | Article 30 Record of Processing Activities; data flow schemas; vendor inventories. |
| 2. Risk Management | Data Protection Impact Assessments (Art. 35); Legitimate Interests Assessments (LIA). |
| 3. Internal Governance | Information Security Policies (ISP); access management matrices; staff training logs. |
| 4. External Relationships | Signed Article 28 DPAs; Standard Contractual Clauses (SCCs) for cross-border transfers. |
| 5. Incident Preparedness | Internal data breach register (Art. 33.5); tested 72-hour notification protocol. |