Data Governance Atlas

The principles, end to end

For both sides

Seven principles that every other obligation hangs off. What each actually requires, where each is usually breached, and why the seventh is different in kind.

NIST PF GV-PID-P
ISO 27701 A.7.2.1A.7.4.1A.7.4.3
GDPR family Art 5(1)(a)-(f)Art 5(2)

Almost every enforcement decision in the GDPR family is, at bottom, a principles decision. The detailed articles are machinery; the principles are what the machinery is for, and a regulator will usually cite both.

The six, plus one

Lawfulness, fairness and transparency. Three requirements in one line, and they are not the same test. Lawfulness is the basis question. Transparency is whether people were told. Fairness is the one with no checklist — it asks whether the processing is within what people would reasonably expect and whether it exploits an imbalance. Processing can be lawful and transparent and still unfair, and fairness is increasingly where novel practices fail.

Purpose limitation. Collect for specified, explicit, legitimate purposes; do not process further in a way incompatible with them. The pressure point is reuse — data collected to deliver a service, later used to train a model or score a customer. Compatibility is assessed on the link between purposes, the context of collection, the nature of the data, the consequences, and the safeguards.

Data minimisation. Adequate, relevant and limited to what is necessary. It applies to fields, to precision, to duration and to how many people can see it. The common failure is collecting because a form already had the field.

Accuracy. Accurate and, where necessary, kept up to date; inaccurate data erased or rectified without delay. A standing duty, not one triggered by a complaint. See rectification in practice.

Storage limitation. Kept in identifiable form no longer than necessary. See retention and deletion.

Integrity and confidentiality. Appropriate security against unauthorised or unlawful processing and against accidental loss, destruction or damage. See technical and organisational measures.

Accountability is the seventh and is different in kind. The first six say what you must do; accountability says you must be able to demonstrate you did it. It converts every other principle into an evidence problem, which is why records, assessments and decision logs matter as much as the underlying behaviour.

Why “we complied” is not a defence

Under accountability, compliance you cannot evidence is functionally indistinguishable from non-compliance. An organisation that genuinely minimised, genuinely assessed the balance and genuinely deleted on schedule — but wrote none of it down — cannot show any of it when asked.

This is the single most useful thing to internalise about the regime: the obligation is not just to be right, it is to be able to show that you were. Every practice in the governance section exists to produce that evidence as a by-product of doing the work, rather than as a separate exercise afterwards.

How they interact

The principles are cumulative, not alternatives. Satisfying one does not offset another:

  • Consent does not rescue excessive collection — a lawful basis does not answer minimisation.
  • A legitimate purpose does not justify indefinite retention.
  • Strong security does not make unnecessary collection proportionate.
  • Transparency does not make unfair processing fair; telling people you will do something objectionable does not make it acceptable.

When testing a proposal, run all seven in order rather than stopping at the first that passes. Most failures are found at minimisation and storage limitation, and most arguments happen at fairness.

Reading a decision

When a regulator publishes a finding, the principles cited tell you what kind of failure it was. Art 5(1)(a) with Art 6 is a basis failure. Art 5(1)(c) is “you took too much”. Art 5(1)(e) is “you kept it too long”. Art 5(1)(f) with Art 32 is a security failure. Art 5(2) appearing alongside any of them usually means the organisation could not produce the evidence — and that is often what turned a finding into a fine.

How this differs elsewhere

The page above is written from a GDPR-family default. These are the recorded departures — family entries apply to every jurisdiction in that family at once.

US state privacy acts Does not apply Applies to the whole US state acts

No general principles article. Comparable duties exist but are scattered through specific obligations rather than stated as overarching principles.

There is no equivalent of a single provision setting out lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity and accountability. Purpose limitation and minimisation appear as duties tied to disclosed purposes; security appears as a reasonableness standard; there is no free-standing accountability principle requiring you to demonstrate compliance across the board, though risk assessments are mandated for defined higher-risk activities.

Where this connects

Sources

Never independently verified.