Fiche 14/54
Part 2 — Core Principles
Intermediate
Reviewed 2026-08-23
The 6 Cardinal Principles of Processing (Art. 5.1)
The 6 Cardinal Processing Principles (Art. 5.1)
⚡ In 30 seconds
Article 5(1) GDPR lays down the non-negotiable core of data protection: 1. Lawfulness, fairness, and transparency · 2. Purpose limitation · 3. Data minimisation · 4. Accuracy · 5. Storage limitation · 6. Integrity and confidentiality. Under Article 5(2), the controller must be able to demonstrate compliance with each principle at any time.
| Principle | Regulatory Core Requirement | Operational Consequence |
|---|---|---|
| Lawfulness, Fairness, Transparency | Art. 5(1)(a): Valid legal ground; fair and open dealings with individuals. | Clear privacy notices; strictly no dark patterns or covert tracking. |
| Purpose Limitation | Art. 5(1)(b): Specific, explicit, and legitimate purposes; no incompatible reuse. | Siloing data; prohibition of arbitrary repurposing for unstated ventures. |
| Data Minimisation | Art. 5(1)(c): Adequate, relevant, and limited to what is necessary. | Stripping optional form fields; automated payload pruning in APIs. |
| Accuracy | Art. 5(1)(d): Accurate and kept up to date; swift rectification. | Correction workflows; address validation; bounce-management routines. |
| Storage Limitation | Art. 5(1)(e): Kept in identifiable form no longer than strictly needed. | Automated database purges; distinct intermediate archive storage tiers. |
| Integrity & Confidentiality | Art. 5(1)(f): Protection against unauthorized access, loss, or destruction. | End-to-end TLS, at-rest AES encryption, 2FA, granular access controls. |