Fairness (Article 5(1)(a) GDPR)
The fairness principle of the GDPR: the controller's duty of consideration, the prohibition of manipulative design (dark patterns) and the priority of open, direct collection.
In addition to lawfulness and transparency, Article 5(1)(a) GDPR requires that personal data be processed fairly. The English language version ("fairness") captures the substance of the principle better than the German wording ("Treu und Glauben"): at its core, it is a fairness requirement that shapes the controller's conduct throughout the entire processing operation.
Key takeaways
- Fairness (in German "Treu und Glauben") is a general duty of consideration owed by the controller to the interests of the data subject.
- The controller must not abuse trust and must not exploit misconceptions ("prohibition on obtaining data by subterfuge", "prohibition of surprise").
- Dark patterns are prohibited: decision alternatives must be presented in a neutral and equivalent manner, and refusal must not be made more difficult.
- The principle calls for a priority of open, direct collection from the data subject; covert or indirect collection must be objectively justified.
- It shapes the interpretation of the information obligations (Articles 13 and 14 GDPR), of consent (Article 7 GDPR) and of Article 25 GDPR.
1 Overview
1.1 Content of the principle
The principle of processing in a fair manner gives expression to the fundamental rights requirement laid down in Article 8(2), first sentence, of the Charter of Fundamental Rights of the European Union (CFR). It can be understood as a general duty of consideration for the interests of the data subject and is, to that extent, an expression of the principle of proportionality.
The controller must take the interests and expectations of the data subject into account and must not disregard them without good reason, must not abuse the data subject's trust and must not exploit any misconceptions on the part of the data subject. The commentary literature has coined the terms "prohibition on obtaining data by subterfuge" and "prohibition of surprise" for this.
1.2 Relationship to transparency
The principle is closely connected with transparency. Article 13(2) and Article 14(2) GDPR attach additional information obligations to whether the information is necessary to ensure "fair and transparent processing". To that extent, transparency is one aspect of the fairness requirement, but it was expressly included in Article 5(1)(a) GDPR as a separate principle.
2 Areas of application
2.1 Concealed legal bases
A typical breach of the principle occurs where the controller obtains consent even though another legal basis (such as Article 6(1)(b) or (f) GDPR) in fact applies, and does not inform the data subject of this. The data subject gives consent in the mistaken belief that they retain control over their data because they can withdraw it at any time. The EDPB Guidelines 5/2020 on consent expressly address this problem (EDPB, Guidelines 05/2020 on consent under Regulation 2016/679, of 4 May 2020, paras. 121 et seq.).
2.2 Manipulative design (dark patterns)
The principle prohibits the controller from designing decision-making situations in a manipulative way. This concerns in particular the practice of so-called "dark patterns" (design or functional tricks used to steer a data subject's decision in a particular direction). Under Article 25(1) GDPR, the data protection principles must be taken into account as early as the design of the data processing. It follows in particular that:
- Decision alternatives must be presented in a neutral and equivalent manner.
- Refusing consent must not be made more difficult than necessary compared with giving it.
- The data subject must not be "worn down" by repeated consent requests (for example by cookie banners that reappear on every subpage until the data subject consents out of exasperation).
2.3 Facilitating the exercise of rights
It follows from the principle that the controller must not make it excessively difficult for the data subject to exercise their informational self-determination. The obligation under Article 12(2) GDPR to facilitate the exercise of data subject rights can be understood as a concretization of the principle.
2.4 Open collection of data
Consideration for the interests and rights of the data subject also requires that the data subject be protected against opaque processing operations. This gives rise to a priority of open collection and of direct collection from the data subject, because this form of collection offers the greatest degree of comprehensibility and control. Where the controller collects the data from third parties or even covertly, although direct or open collection would be possible, this requires specific justification.
Whether Article 5(1)(a) GDPR gives rise to a separate "principle of direct collection" is disputed in the literature. Irrespective of this, the principle of fairness operates in the individual case as a burden of justification: covert or indirect collection must be objectively justified.
3 Relationship to other obligations
The principle radiates into numerous individual obligations under the GDPR. It shapes the interpretation of the information obligations under Articles 13 and 14 GDPR, the design of consent under Article 7 GDPR and the requirements for data protection by design and by default under Article 25 GDPR.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Lawfulness (Article 5(1)(a) GDPR)
Lawfulness as a principle relating to processing: the need for a legal basis, the relationship to Article 6 GDPR, and the requirement that legal bases be clear and precise.
Transparency (Article 5(1)(a) GDPR)
The GDPR's principle of transparency: retrospective and prospective comprehensibility of the processing, substantive and linguistic requirements for the information provided to data subjects.