The Six Data Processing Principles of the UK GDPR Explained

Article 5 of the UK GDPR (General Data Protection Regulation) sets out six key data processing principles. These principles underpin all personal data processing and serve as a framework for ensuring compliance with the GDPR.

This article discusses the six principles and explains how they apply in practice. We can also offer guidance on how to demonstrate compliance.

The Principles

There are six with an added seventh.

  1. Lawful, fair and transparent
  2. Purpose limitation
  3. Data minimisation
  4. Accuracy of data
  5. Limitation on storage
  6. Integrity and confidentiality
  7. Acountability

Lawfulness, fairness and transparency

  • Lawful – You must identify and apply at least one lawful basis for processing, such as consent, performance of a contract, or legal obligation. Your processing must not breach any other applicable laws.
  • Fair – Individuals must not be misled, harmed, or disadvantaged in unexpected ways through the processing of their data.
  • Transparent – You must be open about how you collect and use personal data. This is usually achieved through clear, accessible privacy notices or similar communications.

Purpose Limitation

This principle requires that personal data is:

  • Collected for specified, explicit and legitimate purposes; and
  • Not processed further in ways that are incompatible with those original purposes.

You must make your processing purposes clear from the outset and record them. If you later wish to use the data for a different purpose, you may only do so if the new purpose is compatible. This would be based on a legal obligation. Alternatively, you may wish to obtain fresh consent.

Data Minimisation

Your business must ensure that the data they process is:

  • Adequate – sufficient to fulfil the stated purpose;
  • Relevant – clearly connected to that purpose;
  • Limited – not excessive in scope or volume.

Only collect the data you need to do your job. Too much data increases risk and this must be avoided. Should a breach occur, good data minimisation practise can minimise exposure.

Accuracy

This principle requires you to take “every reasonable step” to ensure that personal data is:

  • Correct and complete;
  • Updated where necessary;
  • Rectified or erased promptly if found to be inaccurate.

The level of accuracy required depends on the purpose of the processing. For example, address details for a one-off delivery may not need to be maintained over time. However, payroll information must be maintained.

A data subject may challenge the accuracy of their data. In this case you should investigate and, where appropriate, amend the data without delay. Keeping records of such actions helps support accountability.

Storage limitation

You must not retain personal data for longer than is necessary. This means:

  • Defining and documenting retention periods for different data types;
  • Reviewing stored data periodically to ensure continued relevance;
  • Securely disposing of data once it is no longer required.

This is achieved by the use of a data retention schedule and accompanying policy. This document sets out how long data will be retained for and the reasons for doing so. A regular review should take place, at least annually and data decisions can be made. If you choose to delete or destroy data, this must be done security and recorded on a data deletion register. Care must be take not to create another record of the data.

Integrity and confidentiality

The integrity and confidentiality principle states that personal data is:

  • Processed securely; and
  • Protected against unauthorised access, unlawful use, accidental loss, destruction or damage.

This begins with you! Be careful when out of the office, lock your machine and avoid free wi-fi without proper protection.

For your business, this means conducting risk assessments, applying security controls (such as encryption, access controls, firewalls and malware protection) and developing robust policies and training for staff.

Availability, in other words, ensuring data is accessible when needed, is also often considered alongside integrity and confidentiality as part of the ‘CIA triad’ in information security.

Combining technical controls with organisational measures creates a layered approach to security and helps demonstrate compliance.

The ‘seventh principle’: accountability

In addition to the six named principles, the UK GDPR introduces an overarching requirement: accountability.

This principle requires organisations not just to comply, but to be able to demonstrate that they comply. In practical terms, this involves:

  • Documenting lawful bases and processing activities;
  • Maintaining privacy notices and staff training records;
  • Keeping data protection policies, procedures and contracts up to date;
  • Conducting Data Protection Impact Assessments (DPIAs) where required;
  • Monitoring processing activities, logging security incidents and keeping breach records.

Organisations are also encouraged to appoint a Data Protection Officer (DPO). Alternatively, assign data protection responsibilities to a suitable person. This is particularly important where processing is large-scale or involves special category data.

The UK GDPR does not mandate any particular certification. However, adopting recognised frameworks such as Cyber Essentials and Cyber Essentials Plus is a good starting point. ISO/IEC 27001 can further demonstrate commitment to good data governance and compliance.