Skip to content
compliancebase
GDPRChapter II — Principles Relating to Processing of Personal Data

Article 5

Principles Relating to Processing of Personal Data

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Apply lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability throughout processing.

Points of focus

  • Tie collection to explicit purposes and lawful bases
  • Limit data, access, and retention to what those purposes require
  • Demonstrate compliance through owned records and controls

Implementation notes

Give each personal-data field an owner, purpose, lawful basis, recipients, and retention rule; enforce minimisation in event schemas and verify deletion across primary, derived, and support stores. Operationalize tie collection to explicit purposes and lawful bases in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain purpose and lawful-basis register linked to product fields with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that analytics collects identifiers because they might be useful later Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample purpose and lawful-basis register linked to product fields with dates and named reviewers. Be ready to walk through how you detect and correct: analytics collects identifiers because they might be useful later

Evidence auditors typically request:

  • Purpose and lawful-basis register linked to product fields
  • Retention schedule and deletion-job results
  • Data minimisation reviews for forms, events, and logs

Common gaps

  • Analytics collects identifiers because they might be useful later
  • A retention policy exists but production backups and support exports ignore it

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 5This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Principles Relating to Processing of Personal Data applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — tie collection to explicit purposes and lawful bases — with evidence stored where auditors and customers can sample it.

Lead with purpose and lawful-basis register linked to product fields and pair it with retention schedule and deletion-job results. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because analytics collects identifiers because they might be useful later Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above