Article 5
Principles Relating to Processing of Personal Data
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Apply lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability throughout processing.
Points of focus
- Tie collection to explicit purposes and lawful bases
- Limit data, access, and retention to what those purposes require
- Demonstrate compliance through owned records and controls
Implementation notes
Give each personal-data field an owner, purpose, lawful basis, recipients, and retention rule; enforce minimisation in event schemas and verify deletion across primary, derived, and support stores. Operationalize tie collection to explicit purposes and lawful bases in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain purpose and lawful-basis register linked to product fields with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that analytics collects identifiers because they might be useful later Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample purpose and lawful-basis register linked to product fields with dates and named reviewers. Be ready to walk through how you detect and correct: analytics collects identifiers because they might be useful later
Evidence auditors typically request:
- Purpose and lawful-basis register linked to product fields
- Retention schedule and deletion-job results
- Data minimisation reviews for forms, events, and logs
Common gaps
- Analytics collects identifiers because they might be useful later
- A retention policy exists but production backups and support exports ignore it
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 5 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 5: Regulation (EU) 2016/679, Article 5 — Principles Relating to Processing of Personal Data