If you’ve heard about data privacy, you’ve no doubt heard about the GDPR. There are 7 key principles that form its foundation:

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality (security)
  • Accountability

These principles are set out at the very beginning of the legislation and are the building blocks for the rest of it. They’re what your privacy policy needs to be based on to ensure it’s GDPR compliant. Let’s take a closer look at each.

GDPR compliance badge with EU stars

1. Lawfulness, Fairness and Transparency

According to the GDPR, personal data shall be:

“processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness, transparency’)”

: Article 5.1(a) GDPR

You need to satisfy all three elements of this principle: lawfulness, fairness, and transparency.

Lawfulness

To satisfy the lawfulness aspect, you must identify grounds for processing any personal data. There are six lawful bases for processing, and at least one must apply:

  1. Consent: the individual has consented to processing of their personal data.
  2. Contract: processing is necessary to fulfil a contract with the individual, or at their request before entering into one.
  3. Legal obligation: you must process the information to comply with the law.
  4. Vital interests: processing is necessary to protect someone’s life.
  5. Public task: processing is necessary to perform a task in the public interest or an official function, with a clear legal basis.
  6. Legitimate interests: processing is required for the legitimate interests of you or a third party, unless overridden by the individual’s interests.

Fairness

Fairness means only processing and handling personal data in ways the individual would expect, with no negative effects on them as a result.

Another aspect of fairness is how the information was obtained, the individual must be aware of why and how their personal data is being collected. Data obtained through unjust means is unlikely to satisfy the fairness element.

Transparency

Being transparent means being open, honest, and clear about how you collect, use, and manage personal data. This information must be easily accessible and written in clear, easily understood language; it’s part of your privacy policy, which needs to be placed somewhere obvious on your website.

To comply with lawfulness, fairness, and transparency, you must:

  1. Identify a lawful reason for processing
  2. Identify a condition for processing special category or criminal offence data
  3. Only use personal data for lawful purposes
  4. Consider the impact of processing on the people whose data it is, and justify any negative impact
  5. Process personal data in expected ways, or explain why you’re processing it for other reasons
  6. Avoid being deceptive or misleading in how you collect personal data
  7. Be open and honest about the collection and use of personal data

2. Purpose Limitation

The second key principle states that personal data shall be:

“collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’)”

: Article 5.1(b) GDPR

This means you must be clear about why you collect personal data and how you use it, and if you use it for a different reason than originally specified, that use must still be fair, lawful, and transparent.

To comply, you’ll need to:

  1. Identify the purpose for processing
  2. Document the purpose
  3. Include the reason for collecting personal data in your privacy policy
  4. Ensure any new use of personal data is either compatible with the original purpose, or get fresh consent for the new purpose

3. Data Minimisation

The third key principle states that personal data shall be:

“adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’)”

: Article 5.1(c) GDPR

This means you must collect the least amount of personal data needed to fulfil its intended purpose. Holding more data than required is a breach of this principle.

To comply, you’ll need to:

  1. Collect personal data only when needed for a specific purpose
  2. Hold only enough personal data to fulfil that purpose
  3. Review the data periodically and delete anything unnecessary

4. Accuracy

The fourth key principle states that personal data shall be:

“accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’)”

: Article 5.1(d) GDPR

This requires you to ensure the accuracy of any personal data you collect, and that it remains valid and fit for purpose.

To comply, you’ll need to:

  1. Ensure the accuracy of any personal data collected
  2. Update the data as required
  3. Keep records of any mistakes
  4. Comply with the right to rectification

5. Storage Limitation

The fifth key principle states that personal data shall be:

“kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’)”

: Article 5.1(e) GDPR

This means you can’t hold data for longer than required, and must be able to justify why you’re storing it. Personal data may be held longer if it’s kept for public interest archiving, scientific or historical research, or statistical purposes.

To comply, you’ll need to:

  1. Know what personal data you hold
  2. Know why you hold it
  3. Be able to justify how long you retain it
  4. Erase or anonymise any personal data no longer required
  5. Have a process in place for requests to have personal data erased

6. Integrity and Confidentiality (Security)

The sixth key principle, also known as the security principle, states that personal data shall be:

“processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)”

: Article 5.1(f) GDPR

To comply, you need to:

  1. Determine the level of security required, based on the type and amount of personal information processed
  2. Have a security policy, and follow it
  3. Have basic technical controls in place to reduce cyberattacks
  4. Use encryption when appropriate
  5. Understand the confidentiality, integrity, and availability of the personal data you process
  6. Have an appropriate backup process in place in case personal data is lost
  7. Conduct regular reviews of your security measures, and adjust your procedures as needed

7. Accountability

The seventh key principle, under Article 5.2 of the GDPR, states:

“The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).”

: Article 5.2 GDPR

There are two key points here: you must be responsible for, and comply with, the GDPR; and you must be able to demonstrate how you comply.

To demonstrate compliance, you’ll need to:

  1. Keep evidence of how you comply with the GDPR
  2. Ensure your privacy policy is GDPR compliant
  3. Have a data protection policy in place, if applicable
  4. Use a data-protection-by-design approach, implementing best practices throughout your processing operations
  5. Implement appropriate security measures
  6. Record and report any personal data breaches
  7. Appoint a Data Protection Officer, if required

To ensure your business is GDPR compliant, follow these seven key principles as closely as possible. Generate your own GDPR-compliant privacy policy using our free generator.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.