Data Protection HubIndividual TopicsPrinciples Relating to Processing

Accountability (Article 5(2) GDPR)

Accountability as a principle of the GDPR: compliance with the principles and the ability to demonstrate it, documentation obligations, retention period, burden of proof borne by the controller.

Under Article 5(2) GDPR, the controller is responsible for compliance with the principles set out in paragraph 1 and must be able to demonstrate such compliance. The principle combines the two central aspects of the concept of accountability (Article 29 Working Party, WP 173, Opinion 3/2010 on the principle of accountability, of 13 July 2010).

Key takeaways

  • Accountability has two dimensions: compliance with the principles of Article 5(1) GDPR and the ability to demonstrate that compliance.
  • What is new compared with the Data Protection Directive is solely the obligation to demonstrate compliance; Article 24(1) GDPR extends it to compliance with the GDPR as a whole.
  • Demonstrating compliance requires documentation, for example records of processing activities, evidence of consent, data protection, erasure and access authorization concepts as well as DPIA documentation.
  • The standard is risk-based: the more intrusive the processing, the higher the requirements.
  • An infringement is subject to administrative fines; in addition, the controller bears the burden of pleading and proving compliance with the principles.

1 Overview

1.1 Innovation compared with the directive

The obligation to comply with the principles already existed under Article 6 of Data Protection Directive 95/46/EC. What has been added is the obligation to demonstrate compliance. Article 5(2) GDPR refers only to the principles set out in paragraph 1; Article 24(1) GDPR extends the requirement to compliance with the GDPR as a whole.

An infringement of the accountability obligation is subject to administrative fines. Beyond that, the principle has an effect on the burden of pleading and proof in disputes. In Orange România, the CJEU expressly confirmed that the controller must demonstrate that the processing is based on a valid legal basis (CJEU, judgment of 11 November 2020, C-61/19, Orange România, para. 42).

2 Content of the obligation

2.1 Two dimensions

The principle of accountability contains two dimensions:

  • Compliance: the controller must observe the principles set out in Article 5(1) GDPR.
  • Demonstrability: the controller must be able to demonstrate that compliance to supervisory authorities and, where applicable, in disputes with data subjects.

Demonstrating compliance requires documentation of the processing and of the measures taken to ensure compliance. Typical instruments are the records of processing activities (Article 30 GDPR), the documentation of consent (Article 7(1) GDPR), data protection concepts, erasure and access authorization concepts as well as the documentation of data protection impact assessments (Article 35 GDPR).

2.2 Risk-based approach

Article 24(1) GDPR makes the standard clear: the controller must (depending on the risk that its data processing poses to the rights and freedoms of data subjects) implement appropriate technical and organizational measures to ensure and to be able to demonstrate that processing is performed in accordance with the GDPR. The requirements increase with the intrusiveness of the processing.

Accountability is an expression of the controller's own responsibility. The GDPR abolished the traditional obligation to notify processing operations before they commence and replaced it with the risk-oriented approach of the data protection impact assessment (Article 35 GDPR) and the subsequent consultation of the supervisory authority (Article 36 GDPR).

3 Retention and burden of pleading

3.1 Retention period

The GDPR does not lay down a general retention period. In practice, a minimum period of three years is proposed, derived from the limitation period for prosecution under § 31(3), first sentence, of the German Act on Regulatory Offenses (OWiG). For certain areas (such as the documentation of consent or the logging of particularly sensitive processing operations), however, different periods may be appropriate.

3.2 Burden of pleading and proof

Accountability entails a burden of pleading and proof on the part of the controller insofar as compliance with the principles of Article 5(1) GDPR is concerned. This follows from the very fact that the actual motives and considerations behind a processing operation lie within the controller's sphere. The position is different for circumstances that by their nature originate from the data subject's sphere (such as the particular situation relied on in the context of the right to object under Article 21(1) GDPR, the existence of which the data subject must set out).

4 Interaction with the other principles

Accountability operates as a cross-cutting principle. It requires the controller not merely to comply with all the other principles, but to document that compliance in such a way that it can be substantiated vis-à-vis third parties.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn