Get Demo
↑

The 7 GDPR Principles (Article 5) Explained with Examples

Article 5(1)(a–f) lists seven processing principles plus accountability in Article 5(2) — with practical examples for controllers and processors.

Published: September 2026 Compliance · GDPR 8–12 min read

Article 5 is the spine of the GDPR. Controllers and processors must process personal data according to the seven principles in Article 5(1)(a–f), and Article 5(2) adds accountability — you must be able to demonstrate compliance, not merely claim it.

Related: GDPR hub · Lawful bases · Data subject rights · CSA for GDPR.

Locked structure: Seven principles in Article 5(1)(a–f) + accountability in Article 5(2). Fines for core principle infringements sit in the higher Art 83 tier (up to €20M or 4% worldwide annual turnover, whichever is higher).

The Seven Principles (Article 5(1)(a–f))

Letter
Principle
Plain-English example
(a)
Lawfulness, fairness and transparency
Tell people what you do; process only with a valid Article 6 basis
(b)
Purpose limitation
Collect for stated purposes; do not silently repurpose for unrelated marketing
(c)
Data minimisation
Ask only for fields needed for the purpose (no “collect everything” CRM)
(d)
Accuracy
Correct stale addresses and employee records; honour rectification requests
(e)
Storage limitation
Delete or anonymise when retention clocks expire — see retention schedule
(f)
Integrity and confidentiality
Article 32 security: encryption, access control, logging, resilience

Accountability (Article 5(2))

Accountability is not a eighth “soft” principle — it is the duty to demonstrate that 5(1) is met. Typical artefacts: RoPA (Art 30), policies, DPIAs (Art 35), DPAs (Art 28), training records, and audit trails for DSARs and breaches.

How CyberSilo Helps

Turn Principles into Evidence

Map every processing activity to Article 5 and keep accountability artefacts ready for supervisory questions.

Frequently Asked Questions

How many GDPR principles are there?

Seven in Article 5(1)(a–f), plus accountability in Article 5(2).

Is accountability a separate principle?

Article 5(2) requires the controller to be able to demonstrate compliance with 5(1). It is commonly taught alongside the seven principles.

Which fine tier applies to Article 5 breaches?

Infringements of the basic principles often fall under the higher Article 83 tier — up to €20M or 4% of worldwide annual turnover, whichever is higher.

GDPR hub · Lawful basis · Article 32 · Fines · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!