General Data Protection Regulation, Principles Relating to Processing of Personal Data and Accountability (Article 5)
Regulation (EU) 2016/679, Art. 5
In force since .
A comprehensive regime rule binding public and private bodies.
- Obligation class
- Governance, Retention, Security, Disclosure
As of .
What it requires
- If you process personal data, apply the principles in Article 5(1) to that processing; if you are the controller, you are responsible for compliance with them and must be able to demonstrate it (Article 5(1) and (2)).
- Process personal data lawfully, fairly and in a transparent manner in relation to the data subject (Article 5(1), point (a)).
- Collect personal data for specified, explicit and legitimate purposes and do not further process it in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is not considered incompatible, in accordance with Article 89(1) (Article 5(1), point (b)).
- Limit personal data to what is adequate, relevant and necessary in relation to the purposes for which it is processed, data minimization (Article 5(1), point (c)).
- Keep personal data accurate and, where necessary, up to date, and take every reasonable step to ensure that inaccurate personal data, having regard to the purposes for which it is processed, are erased or rectified without delay (Article 5(1), point (d)).
- Keep personal data in a form which permits identification of data subjects for no longer than is necessary for the purposes for which it is processed, storage limitation; store it for longer only insofar as it will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject to the technical and organizational measures the Regulation requires to safeguard the rights and freedoms of the data subject (Article 5(1), point (e)).
- Process personal data in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures (Article 5(1), point (f)).
- If you are the controller, be responsible for, and be able to demonstrate compliance with, each of the principles in Article 5(1) (Article 5(2)).
If you get it wrong
Private right of actionYes
Penalty structure
Article 83(5)(a) names the basic principles for processing pursuant to Articles 5, 6, 7 and 9 among the provisions carrying the higher administrative-fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher.
- Rule
- Higher of
- As of
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
The data protection supervisory authority designated by each EU Member State under Article 51, coordinated on cross-border cases through the one stop shop mechanism, which does not apply to processing by public authorities or by private bodies acting under Article 6(1)(c) or (e) (Article 55(2)), and through the European Data Protection Board (Articles 68-76).
What this law does
Article 5(1), point (a), provides that personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject. Article 5(1), point (b), provides that personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
Article 5(1), point (c), provides that personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Article 5(1), point (d), provides that personal data shall be accurate and, where necessary, kept up to date, and that every reasonable step must be taken to ensure that inaccurate personal data are erased or rectified without delay.
Article 5(1), point (e), provides that personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
Article 5(1), point (e), also provides that personal data may be stored for longer periods insofar as they will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject to the appropriate technical and organizational measures the Regulation requires in order to safeguard the rights and freedoms of the data subject.
Article 5(1), point (f), provides that personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures. Article 5(2) provides that the controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1.
Article 83(5), point (a), subjects infringements of the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9 to administrative fines up to EUR 20,000,000 or, in the case of an undertaking, up to 4 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher.
Article 82(1) gives any person who has suffered material or non-material damage as a result of an infringement of the Regulation the right to receive compensation from the controller or processor for the damage suffered. Article 79(1) gives each data subject the right to an effective judicial remedy where he or she considers that his or her rights under the Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with the Regulation. Article 99(2) provides that the Regulation applies from .
When LexLint raises it
When your app profile says your app crawls the web, trains models, generates content with AI, deploys a chatbot, sends automated outreach, makes high-risk automated decisions, processes voice recordings or processes biometric data.