# Principles Relating to Processing (Article 5 GDPR)

Overview of the principles relating to the processing of personal data under Article 5 GDPR: legal nature, addressees, relationship to Article 6 GDPR, exceptions and exposure to administrative fines.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung
> Sprache: en



Article 5 GDPR establishes a catalog of basic obligations that every processing of personal data must satisfy. The principles go back to Article 8(2) of the Charter of Fundamental Rights of the European Union (CFR) and, together with the legal bases in Article 6 GDPR, form the substantive core of Union data protection law.

<Callout type="info">
  **Key takeaways**

  * Article 5 GDPR contains **nine principles**: eight substantive principles in paragraph 1 and the **accountability** obligation in paragraph 2.
  * Every processing operation must satisfy the principles and, **in addition**, a legal basis under Article 6 GDPR; the two assessments are **cumulative**.
  * The principles in paragraph 1 bind every body that carries out processing, and therefore also the **processor**; the accountability obligation applies only to the controller.
  * Infringements are subject to administrative fines in the **highest tier** under Article 83(5)(a) GDPR (up to EUR 20 million or 4% of annual turnover).
  * Exceptions are possible only within narrow limits, under Article 23 GDPR (national restrictions) and Article 85 GDPR (media privilege).
</Callout>

## 1 Overview [#1-overview]

### 1.1 Legal consequence and systematic context [#11-legal-consequence-and-systematic-context]

Every processing of data must satisfy both the principles of Article 5 GDPR and a legal basis under Article 6 GDPR. The principles describe the **quality** of the processing, Article 6 GDPR its **permissibility**. In settled case law, the CJEU maintains that both assessments must be satisfied cumulatively.

The principles are neither mere programmatic statements nor mere optimization requirements; they are binding basic obligations of the controller. Their binding force follows directly from Article 8(2) CFR, which itself names several of these principles (consent or a basis laid down by law, specification of the purpose, and fairness).

### 1.2 The nine principles in detail [#12-the-nine-principles-in-detail]

Article 5(1) GDPR names six substantive principles; point (a) additionally contains two further independent requirements:

| Principle                     | Provision            |
| ----------------------------- | -------------------- |
| Lawfulness                    | Article 5(1)(a) GDPR |
| Processing in a fair manner   | Article 5(1)(a) GDPR |
| Transparency                  | Article 5(1)(a) GDPR |
| Purpose limitation            | Article 5(1)(b) GDPR |
| Data minimization             | Article 5(1)(c) GDPR |
| Accuracy                      | Article 5(1)(d) GDPR |
| Storage limitation            | Article 5(1)(e) GDPR |
| Integrity and confidentiality | Article 5(1)(f) GDPR |
| Accountability                | Article 5(2) GDPR    |

Compared with Article 6 of Data Protection Directive 95/46/EC, the principles of transparency and of integrity and confidentiality as well as the accountability obligation are new. In parallel to Article 5 GDPR, largely identical provisions exist in Article 4(1) of Directive (EU) 2016/680 (transposed in § 47 of the German Federal Data Protection Act (BDSG)) and in Article 4 of Regulation (EU) 2018/1725 for the institutions and bodies of the Union.

### 1.3 Addressees [#13-addressees]

Article 5(2) GDPR expressly assigns the accountability obligation to the controller. The principles of paragraph 1, by contrast, are addressed to every body that processes personal data, and therefore also to the processor. Where the GDPR imposes obligations on the processor separately (for example through Articles 28 and 32 GDPR), those rules give concrete form to the principles for its activity.

### 1.4 Exposure to administrative fines [#14-exposure-to-administrative-fines]

Infringements of the principles of Article 5 GDPR are subject to administrative fines in the highest tier under Article 83(5)(a) GDPR (up to EUR 20 million or 4% of total worldwide annual turnover). The general nature of the principles raises questions of legal certainty in this respect, because in themselves the principles formulate few concrete requirements as to conduct.

## 2 Exceptions to the principles [#2-exceptions-to-the-principles]

### 2.1 National exceptions under Article 23 GDPR [#21-national-exceptions-under-article-23-gdpr]

Article 23(1) GDPR allows national legislatures to provide for exceptions to the principles of Article 5 GDPR, but only "in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22". The restriction is to be measured against the practical effects of the principle concerned: information obligations that may arise from transparency or fairness alongside Articles 13 and 14 GDPR may be restricted; an exception to the principle of storage limitation (Article 5(1)(e) GDPR), by contrast, cannot be based on Article 23(1) GDPR, because that principle has no connection to the rights of data subjects.

### 2.2 Media privilege under Article 85 GDPR [#22-media-privilege-under-article-85-gdpr]

Article 85(2) GDPR allows exceptions from Chapter II of the GDPR (and thus also from Article 5 GDPR) for processing carried out for journalistic, artistic, academic and literary purposes. The Member States have given substance to this opening clause through media and press law, in Germany for example through § 23(1), fourth sentence, of the Interstate Media Treaty (MStV) and the press acts of the Länder.

## 3 Relationship to Article 6 GDPR [#3-relationship-to-article-6-gdpr]

The principle of lawfulness in Article 5(1)(a) GDPR refers to Article 6 GDPR, which sets out the specific legal bases for processing. The remaining principles impose independent requirements alongside it. As a result, processing may be impermissible despite a valid legal basis if, for example, it infringes data minimization or storage limitation.

<Callout type="info">
  The principles are not exhaustive; they are given concrete form by a large number of specific obligations under the GDPR. Article 25 GDPR (data protection by design), Article 32 GDPR (security of processing) and Articles 13 and 14 GDPR (information obligations) translate the principles into concrete requirements as to conduct.
</Callout>

## 4 The individual principles in the hub [#4-the-individual-principles-in-the-hub]

<Cards>
  <Card title="Lawfulness" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.1-rechtmaessigkeit" description="Article 5(1)(a) GDPR: the need for a legal basis." />

  <Card title="Fairness" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.2-treu-und-glauben" description="Article 5(1)(a) GDPR: fairness, dark patterns, open collection of data." />

  <Card title="Transparency" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.3-transparenz" description="Article 5(1)(a) GDPR: making the processing comprehensible." />

  <Card title="Purpose limitation" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.4-zweckbindung" description="Article 5(1)(b) GDPR: specification of the purpose and change of purpose." />

  <Card title="Data minimization" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.5-datenminimierung" description="Article 5(1)(c) GDPR: relevance, necessity, proportionality." />

  <Card title="Accuracy" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.6-richtigkeit" description="Article 5(1)(d) GDPR: accuracy and currency of the data." />

  <Card title="Storage limitation" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.7-speicherbegrenzung" description="Article 5(1)(e) GDPR: obligation to erase once the purpose has been achieved." />

  <Card title="Integrity and confidentiality" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.8-integritaet-und-vertraulichkeit" description="Article 5(1)(f) GDPR: data security as a principle." />

  <Card title="Accountability" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.9-rechenschaftspflicht" description="Article 5(2) GDPR: demonstrating compliance, accountability." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.