# Data protection principles and the accountability obligation

> **Key takeaway:** Art 5(1): lawful/fair/transparent, purpose-limited, minimised, accurate, storage-limited, secure. Art 5(2): accountability — must be able to demonstrate compliance via records of processing (Art 30), policies, and evidence, not just assert it.

- **Jurisdiction:** England & Wales
- **Practice area:** Commercial
- **Last reviewed:** 2026-09-05
- **Interactive page:** https://www.kttclegal.info/library/notes/Commercial/data-protection-principles-and-accountability
- **Keywords:** data protection principles, Article 5, accountability, purpose limitation, data minimisation, storage limitation, records of processing, UK GDPR

## What is this about?

Article 5 UK GDPR sets out seven principles that govern all processing of personal data. The seventh, accountability, is distinct from the other six in that it requires a controller to be able to demonstrate compliance, not merely achieve it — turning the other principles into a documentation and governance exercise, not just a substantive one.

## What is the core rule?

Article 5(1) requires personal data to be processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes and not further processed incompatibly (purpose limitation); adequate, relevant and limited to what is necessary (data minimisation); accurate and kept up to date; kept no longer than necessary (storage limitation); and processed with appropriate security (integrity and confidentiality). Article 5(2) adds the accountability principle: the controller is responsible for, and must be able to demonstrate compliance with, Article 5(1). In practice this is discharged through records of processing activities (Art 30), data protection policies, staff training, a documented lawful basis for each purpose, and, where required, a Data Protection Officer.

## What are the elements or test?

1. Lawfulness, fairness and transparency: is there a lawful basis, and has the data subject been given the required Art 13/14 privacy information?
2. Purpose limitation: is the data used only for the purpose(s) it was collected for, or a compatible purpose?
3. Data minimisation: is the data collected and retained no more than is necessary for the purpose?
4. Accuracy: are there processes to correct or erase inaccurate data?
5. Storage limitation: is there a retention schedule and is it followed?
6. Integrity and confidentiality: are appropriate technical and organisational security measures in place (Art 32)?
7. Accountability: can the controller produce records of processing, policies, and evidence of compliance on demand?

## Which authorities matter?

- **UK GDPR, Art 5(1)** — States the six substantive principles governing processing.
- **UK GDPR, Art 5(2)** — Imposes the accountability principle — the controller must demonstrate compliance, not just achieve it.
- **UK GDPR, Art 30** — Requires most controllers and processors to maintain a written record of processing activities as the primary evidence of accountability.
- **UK GDPR, Art 32** — Requires appropriate technical and organisational security measures proportionate to risk, underpinning the integrity/confidentiality principle.

## How does this apply in practice?

This note addresses the general principles framework and does not itself cover the specific mechanics of records of processing, DPIAs, or breach notification, each of which has its own note. Small organisations may qualify for limited exemptions from the Art 30 record-keeping duty, but the underlying principles still apply regardless of size. 'Necessary' under minimisation and storage limitation is a genuine constraint, not a subjective business preference — it is tested against the stated purpose.

## What are common pitfalls?

- Collecting data 'just in case it's useful later' — a purpose-limitation and minimisation failure
- Keeping data indefinitely with no retention schedule or deletion process
- Treating accountability as a paperwork afterthought rather than embedding it in each processing decision from the outset
- Assuming a small organisation's Art 30 exemption removes the substantive principles, not just the record-keeping format
- Failing to review and update privacy notices when processing purposes change

## When would a practitioner use this?

Underpins any data protection audit, compliance review, or advice on setting up a new processing activity — the principles are the baseline against which every other data protection question is ultimately assessed.

## Quick reference

Art 5(1): lawful/fair/transparent, purpose-limited, minimised, accurate, storage-limited, secure. Art 5(2): accountability — must be able to demonstrate compliance via records of processing (Art 30), policies, and evidence, not just assert it.

---

*Reference material from [KTTC Legal](https://www.kttclegal.info/), not legal advice. Work product supports instructing solicitors and barristers under their supervision. England & Wales.*
