The six GDPR principles explained
The six GDPR principles are lawfulness, purpose limitation, data minimisation, accuracy, storage limitation and integrity. They are set out in Article 5 of the General Data Protection Regulation and apply to every organisation that processes personal data.
Almost every privacy question that lands on our desk comes back to those six rules. They fit on a single sheet of paper, and in practice they still go wrong all the time.
Since the GDPR came into force in 2018, organisations that collect personal data have taken on more responsibilities. The people whose data it is gained more rights. If you don’t follow the rules, the Dutch Data Protection Authority can impose a fine. And no, this is not just about the big players. The freelancer keeping a client list in a spreadsheet falls under it just as much.
Below we go through all six, and what they mean once you hold them up against your own organisation.
1. Lawfulness, fairness and transparency
You may only process personal data if you have a valid legal basis for doing so. The GDPR sets out six:
- You have the consent of the data subject.
- The processing is necessary to perform a contract.
- You are under a legal obligation to process the data.
- The processing is necessary to protect vital interests.
- You are carrying out a public interest task or exercising official authority.
- You have a legitimate interest in the processing.
Stricter rules apply to criminal data and to special categories of personal data, such as data on someone’s health, race or political opinions. Processing must also be fair and fit within accepted social norms. And data subjects have the right to know what is being processed about them.
Where our clients most often come unstuck is consent. It has to be freely given, specific and unambiguous, and people must be able to withdraw it. A pre-ticked box does not meet that standard. If you are an employer asking your staff for consent, you run into something else. In a relationship of authority, consent is rarely genuinely free, and therefore often invalid.
2. Purpose limitation
Only collect data for a purpose you have defined in advance, which is specific and legitimate. Want to use that same data for something else later on? Then you need a new legal basis for it. Data you gathered for purpose A should not quietly find its way into purpose B.
Think of the address list you built up to deliver orders, which then becomes the foundation for your newsletter. Sounds harmless. It isn’t.
3. Data minimisation
Process as little personal data as you can. No more than is strictly necessary for the purpose you collected it for. More data is not an advantage here, it is a risk.
A practical tip: run through your own forms and ask yourself why each field is there. A date of birth on a newsletter sign-up is hard to justify.
4. Accuracy
Make sure the data you process is correct and up to date. Anyone whose data sits with your organisation may ask you to correct it if it is wrong. You cannot simply set that request aside, and as a rule you have one month to respond.
5. Storage limitation
You don’t keep data longer than you need it for the purpose you collected it for. For each category of personal data you set retention periods. That is not a nice-to-have, it is an obligation.
Recruitment data is a good example. The customary line in the Netherlands is four weeks after the procedure closes. If you want to keep someone on file for longer, you ask their permission, and then a year is allowed.
6. Integrity and confidentiality
Data you process must be properly secured. Access only for those who need it, and protection against loss, unauthorised access or damage. A clear authorisation policy is hardly a luxury here.
When this goes wrong, you find yourself in a very different conversation. One about a data breach and the duty to report it. What to do then is covered in what to do in the event of a data breach.
And then there is accountability
Complying is one thing. Being able to demonstrate that you comply is another. That accountability sits in Article 5(2) and is consistently underestimated.
A record of processing activities, documented retention periods and a privacy statement that matches what you actually do: that is your evidence. Without that documentation you are in a weak position the moment the Dutch Data Protection Authority starts asking questions, even if your day-to-day practice is perfectly sound.
So, six principles you can work through in an afternoon, which will save you years of trouble afterwards. Want to know whether your organisation has them in order? Have a look at our page on privacy law or feel free to get in touch. If you have a processing operation that may require a DPIA, we can look at that in the same conversation.