Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Synthesis: Principles Audit Matrix
Courses Guides Blog Resources News
Français English Nederlands
Fiche 21/54 Part 2 — Core Principles Advanced Reviewed 2026-08-23

Synthesis: Principles Audit Matrix

A practical self-assessment matrix to audit any processing activity against the six cardinal principles of Article 5 and systematically identify the required documentary evidence.

Open in interactive reader
🧪 Operational Tool ⚖️ Article 5 Audit Grid

Principles Compliance & Audit Matrix

⚡ In 30 seconds

This operational audit grid translates the legal standards of Article 5 into concrete verification checkpoints. For every processing pipeline, teams must verify that the required audit question is answered affirmatively and substantiated by contemporaneous documentary evidence.

Principle Key Audit Verification Question Mandatory Evidentiary Proof
1. Lawfulness Is the processing mapped to a valid Article 6 legal ground? Article 30 register entry; documented consent or LIA test.
2. Purpose Limitation Are all active uses compatible with the initial notice? Privacy notices; compatibility assessment record (Art. 6.4).
3. Minimisation Are all collected fields strictly necessary for the service? Form schema review; data dictionary; payload logs.
4. Accuracy Is there an accessible update workflow for individuals? Account profile dashboard; customer service rectification logs.
5. Storage Limitation Are retention schedules defined and automated? Retention policy; automated cron purge scripts; deletion certificates.
6. Security & Integrity Are data encrypted at rest and in transit with access silos? Penetration test reports; TLS certificates; IAM access matrices.
⚡ Key Takeaways
  • Every principle must be supported by an objective, inspectable document.
  • The matrix bridges legal compliance and software engineering specifications.
  • Audit results feed directly into continuous risk management cycles.
⚠️ Common Pitfall

Auditing only technical IT security while neglecting purpose limitation and retention periods.

🛠️ In Practice

Embed this 6-point verification grid into Definition of Done (DoD) criteria for software development.

⚖️ Official Sources: Art. 5, 24, 32 GDPR · EDPB Accountability Benchmarks ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Actionable self-assessment tool for operational business and IT teams.
  • Direct mapping of each principle to its tangible documentary proof.
  • Enables detection of compliance gaps before production deployments.

⚠ Common pitfall: Validating processing workflows based on informal verbal assurances without verifying tangible written artifacts.

→ Actionable practice: Apply this matrix to evaluate your organization's highest-risk data processing systems.

← Accountability & Proactive Responsibility (Art. 5.2 & 24) The 6 Legal Bases for Processing (Art. 6.1) →