Data Protection HubIndividual TopicsPrinciples Relating to Processing

Principles Relating to Processing (Article 5 GDPR)

Overview of the principles relating to the processing of personal data under Article 5 GDPR: legal nature, addressees, relationship to Article 6 GDPR, exceptions and exposure to administrative fines.

Article 5 GDPR establishes a catalog of basic obligations that every processing of personal data must satisfy. The principles go back to Article 8(2) of the Charter of Fundamental Rights of the European Union (CFR) and, together with the legal bases in Article 6 GDPR, form the substantive core of Union data protection law.

Key takeaways

  • Article 5 GDPR contains nine principles: eight substantive principles in paragraph 1 and the accountability obligation in paragraph 2.
  • Every processing operation must satisfy the principles and, in addition, a legal basis under Article 6 GDPR; the two assessments are cumulative.
  • The principles in paragraph 1 bind every body that carries out processing, and therefore also the processor; the accountability obligation applies only to the controller.
  • Infringements are subject to administrative fines in the highest tier under Article 83(5)(a) GDPR (up to EUR 20 million or 4% of annual turnover).
  • Exceptions are possible only within narrow limits, under Article 23 GDPR (national restrictions) and Article 85 GDPR (media privilege).

1 Overview

Every processing of data must satisfy both the principles of Article 5 GDPR and a legal basis under Article 6 GDPR. The principles describe the quality of the processing, Article 6 GDPR its permissibility. In settled case law, the CJEU maintains that both assessments must be satisfied cumulatively.

The principles are neither mere programmatic statements nor mere optimization requirements; they are binding basic obligations of the controller. Their binding force follows directly from Article 8(2) CFR, which itself names several of these principles (consent or a basis laid down by law, specification of the purpose, and fairness).

1.2 The nine principles in detail

Article 5(1) GDPR names six substantive principles; point (a) additionally contains two further independent requirements:

PrincipleProvision
LawfulnessArticle 5(1)(a) GDPR
Processing in a fair mannerArticle 5(1)(a) GDPR
TransparencyArticle 5(1)(a) GDPR
Purpose limitationArticle 5(1)(b) GDPR
Data minimizationArticle 5(1)(c) GDPR
AccuracyArticle 5(1)(d) GDPR
Storage limitationArticle 5(1)(e) GDPR
Integrity and confidentialityArticle 5(1)(f) GDPR
AccountabilityArticle 5(2) GDPR

Compared with Article 6 of Data Protection Directive 95/46/EC, the principles of transparency and of integrity and confidentiality as well as the accountability obligation are new. In parallel to Article 5 GDPR, largely identical provisions exist in Article 4(1) of Directive (EU) 2016/680 (transposed in § 47 of the German Federal Data Protection Act (BDSG)) and in Article 4 of Regulation (EU) 2018/1725 for the institutions and bodies of the Union.

1.3 Addressees

Article 5(2) GDPR expressly assigns the accountability obligation to the controller. The principles of paragraph 1, by contrast, are addressed to every body that processes personal data, and therefore also to the processor. Where the GDPR imposes obligations on the processor separately (for example through Articles 28 and 32 GDPR), those rules give concrete form to the principles for its activity.

1.4 Exposure to administrative fines

Infringements of the principles of Article 5 GDPR are subject to administrative fines in the highest tier under Article 83(5)(a) GDPR (up to EUR 20 million or 4% of total worldwide annual turnover). The general nature of the principles raises questions of legal certainty in this respect, because in themselves the principles formulate few concrete requirements as to conduct.

2 Exceptions to the principles

2.1 National exceptions under Article 23 GDPR

Article 23(1) GDPR allows national legislatures to provide for exceptions to the principles of Article 5 GDPR, but only "in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22". The restriction is to be measured against the practical effects of the principle concerned: information obligations that may arise from transparency or fairness alongside Articles 13 and 14 GDPR may be restricted; an exception to the principle of storage limitation (Article 5(1)(e) GDPR), by contrast, cannot be based on Article 23(1) GDPR, because that principle has no connection to the rights of data subjects.

2.2 Media privilege under Article 85 GDPR

Article 85(2) GDPR allows exceptions from Chapter II of the GDPR (and thus also from Article 5 GDPR) for processing carried out for journalistic, artistic, academic and literary purposes. The Member States have given substance to this opening clause through media and press law, in Germany for example through § 23(1), fourth sentence, of the Interstate Media Treaty (MStV) and the press acts of the Länder.

3 Relationship to Article 6 GDPR

The principle of lawfulness in Article 5(1)(a) GDPR refers to Article 6 GDPR, which sets out the specific legal bases for processing. The remaining principles impose independent requirements alongside it. As a result, processing may be impermissible despite a valid legal basis if, for example, it infringes data minimization or storage limitation.

The principles are not exhaustive; they are given concrete form by a large number of specific obligations under the GDPR. Article 25 GDPR (data protection by design), Article 32 GDPR (security of processing) and Articles 13 and 14 GDPR (information obligations) translate the principles into concrete requirements as to conduct.

4 The individual principles in the hub

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn