Almost every enforcement decision in the GDPR family is, at bottom, a principles decision. The detailed articles are machinery; the principles are what the machinery is for, and a regulator will usually cite both.
The six, plus one
Lawfulness, fairness and transparency. Three requirements in one line, and they are not the same test. Lawfulness is the basis question. Transparency is whether people were told. Fairness is the one with no checklist — it asks whether the processing is within what people would reasonably expect and whether it exploits an imbalance. Processing can be lawful and transparent and still unfair, and fairness is increasingly where novel practices fail.
Purpose limitation. Collect for specified, explicit, legitimate purposes; do not process further in a way incompatible with them. The pressure point is reuse — data collected to deliver a service, later used to train a model or score a customer. Compatibility is assessed on the link between purposes, the context of collection, the nature of the data, the consequences, and the safeguards.
Data minimisation. Adequate, relevant and limited to what is necessary. It applies to fields, to precision, to duration and to how many people can see it. The common failure is collecting because a form already had the field.
Accuracy. Accurate and, where necessary, kept up to date; inaccurate data erased or rectified without delay. A standing duty, not one triggered by a complaint. See rectification in practice.
Storage limitation. Kept in identifiable form no longer than necessary. See retention and deletion.
Integrity and confidentiality. Appropriate security against unauthorised or unlawful processing and against accidental loss, destruction or damage. See technical and organisational measures.
Accountability is the seventh and is different in kind. The first six say what you must do; accountability says you must be able to demonstrate you did it. It converts every other principle into an evidence problem, which is why records, assessments and decision logs matter as much as the underlying behaviour.
Why “we complied” is not a defence
Under accountability, compliance you cannot evidence is functionally indistinguishable from non-compliance. An organisation that genuinely minimised, genuinely assessed the balance and genuinely deleted on schedule — but wrote none of it down — cannot show any of it when asked.
This is the single most useful thing to internalise about the regime: the obligation is not just to be right, it is to be able to show that you were. Every practice in the governance section exists to produce that evidence as a by-product of doing the work, rather than as a separate exercise afterwards.
How they interact
The principles are cumulative, not alternatives. Satisfying one does not offset another:
- Consent does not rescue excessive collection — a lawful basis does not answer minimisation.
- A legitimate purpose does not justify indefinite retention.
- Strong security does not make unnecessary collection proportionate.
- Transparency does not make unfair processing fair; telling people you will do something objectionable does not make it acceptable.
When testing a proposal, run all seven in order rather than stopping at the first that passes. Most failures are found at minimisation and storage limitation, and most arguments happen at fairness.
Reading a decision
When a regulator publishes a finding, the principles cited tell you what kind of failure it was. Art 5(1)(a) with Art 6 is a basis failure. Art 5(1)(c) is “you took too much”. Art 5(1)(e) is “you kept it too long”. Art 5(1)(f) with Art 32 is a security failure. Art 5(2) appearing alongside any of them usually means the organisation could not produce the evidence — and that is often what turned a finding into a fine.