# Accuracy (Article 5(1)(d) GDPR)

Accuracy and up-to-dateness of personal data: proactive rectification, profiling and AI, the treatment of time-related data, and obligations where data have been passed on to third parties.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.6-richtigkeit
> Sprache: en



Under Article 5(1)(d) GDPR, personal data must be "accurate and, where necessary, kept up to date". The principle tends to be treated as a poor relation in the data protection debate, although it is of considerable importance for the data subject: data form the basis of the picture that others form of the data subject and are therefore regularly the basis for decisions.

<Callout type="info">
  **Key takeaways**

  * The accuracy obligation is **proactive**: the controller must rectify or erase inaccurate data on its own initiative, without waiting for a request under Articles 16, 18 GDPR.
  * It covers not only facts, but also **value judgments**, forecasts and correlations, for instance in profiling and in the use of AI.
  * Data must be kept up to date only "**where necessary**"; time-related data concerning a past event remain accurate and must not be distorted.
  * The requirements increase with the **potential for harm**: credit reference agencies and decision-relevant data are subject to a stricter obligation than marketing profiles.
  * **Incomplete** data may also be inaccurate; where the controller rectifies data on its own initiative, the recipients concerned must be informed as appropriate.
</Callout>

## 1 Overview [#1-overview]

### 1.1 Legal consequence and purpose [#11-legal-consequence-and-purpose]

As early as its Census judgment, the German Federal Constitutional Court (BVerfG) warned against personality profiles whose accuracy the data subject is able to verify only inadequately ([BVerfG, judgment of 15 December 1983, 1 BvR 209/83 and others, Census, BVerfGE 65, 1](https://www.servat.unibe.ch/dfr/bv065001.html)). It is precisely this risk that the principle of accuracy addresses. It obliges the controller to represent the processed data correctly and to erase or rectify inaccurate data without delay.

### 1.2 Relationship to Articles 16, 18 GDPR [#12-relationship-to-articles-16-18-gdpr]

The obligation under Article 5(1)(d) GDPR is **proactive**. The controller may not wait until the data subject asserts the right to rectification under Article 16(1) GDPR or the right to restriction of processing under Article 18(1)(a) GDPR. Rather, it must take reasonable steps on its own initiative to erase or rectify inaccurate data without delay ([CJEU, judgment of 16 December 2008, C-524/06, Huber, para. 60](https://curia.europa.eu/juris/liste.jsf?language=de\&num=C-524/06)).

## 2 Scope of the principle [#2-scope-of-the-principle]

### 2.1 Facts and value judgments [#21-facts-and-value-judgments]

The principle covers not only facts, but also **value judgments**, in particular forecasts and correlations. In the context of profiling (Article 4(4) GDPR), that is, the evaluation of persons and their characteristics, such value judgments are playing an ever greater role. Value judgments too can be wrong if they rest on a flawed factual basis, proceed from false premises or are based on incorrect inferences. Whether a correlation, for instance between a particular characteristic and a person's ability to pay, actually exists is a question governed by the principle of accuracy.

### 2.2 Profiling and artificial intelligence [#22-profiling-and-artificial-intelligence]

Recital 71, sixth sentence, GDPR requires that profiling be based on "appropriate mathematical or statistical procedures" and that technical and organizational measures be taken to prevent discrimination and to correct factors that result in inaccuracies in personal data. In the case of self-learning systems and artificial intelligence, it must additionally be ensured that decisions are not based on unsuitable or unrepresentative training data. The German Data Protection Conference (DSK) confirmed these requirements in its Hambach Declaration on Artificial Intelligence ([DSK, Hambach Declaration on Artificial Intelligence of 3 April 2019](https://www.datenschutzkonferenz-online.de/media/en/20190405_hambacher_erklaerung.pdf)).

### 2.3 Keeping data up to date: the words "where necessary" [#23-keeping-data-up-to-date-the-words-where-necessary]

The principle requires data to be up to date only in so far as this is necessary for the purpose of the processing ("where necessary"). Which measures are appropriate to ensure accuracy and to keep data up to date must be determined in each individual case, having regard to the purpose. Data relating to a specific point in time or to a past event need not be updated, because correcting their substance would distort their informational content.

<Callout type="info">
  Data are to be assessed "having regard to the purposes for which they are processed". Minutes of a meeting record what a person said, irrespective of whether the content of that statement is correct. Examination answers reflect the candidate's level of knowledge at the time of the examination ([CJEU, judgment of 20 December 2017, C-434/16, Nowak, para. 54 et seq.](https://curia.europa.eu/juris/document/document.jsf?docid=198059\&doclang=DE)).
</Callout>

## 3 Obligations of the controller [#3-obligations-of-the-controller]

### 3.1 Flow of information within the organization [#31-flow-of-information-within-the-organization]

The controller must ensure by organizational means that information calling into question the accuracy of stored data is actually noticed. This may mean monitoring relevant sources on a regular basis or establishing internal reporting channels so that new information reaches those units that are able to verify the accuracy of the data and, where appropriate, to correct it.

### 3.2 Gradation according to the potential for harm [#32-gradation-according-to-the-potential-for-harm]

As a rule, stricter requirements apply to verifying data in the context of their collection than to verifying existing data holdings. Heightened importance must attach to the accuracy and up-to-dateness of data that are particularly relevant for the data subject, for example because they form the basis of a decision or are transmitted to third parties and inaccuracies are difficult to correct later on. Credit reference agencies and warning databases are therefore subject to a stricter accuracy obligation than, for instance, marketing profiles.

### 3.3 Completeness as part of accuracy [#33-completeness-as-part-of-accuracy]

Data may also be inaccurate if they are **incomplete** and are thereby liable to create a false impression or lead to incorrect decisions. In such cases, completion of the data may be required; Article 16, second sentence, GDPR expressly provides for such a right.

### 3.4 Informing recipients where the controller rectifies data on its own initiative [#34-informing-recipients-where-the-controller-rectifies-data-on-its-own-initiative]

The obligation under Article 19, first sentence, GDPR to inform recipients of rectifications is directly linked to a data subject's right to rectification under Article 16 GDPR. Its wording therefore does not cover the case in which the controller carries out the rectification on its own initiative. At any rate where the rectified item of data is of some significance for the data subject, the principle of accuracy and the principle of fair processing will oblige the controller to make reasonable efforts to inform the recipients.

## 4 Limits of rectification [#4-limits-of-rectification]

Not every item of information that subsequently appears inaccurate must be corrected. Where an item of data relates to a specific point in time or to a past event, it remains accurate "having regard to the purposes for which it is processed", even if the underlying circumstances have changed since. German administrative case law has confirmed this distinction, for example in relation to subsequent changes of name in personnel files.

<Cards>
  <Card title="Rectification" href="/docs/dsgvo-hub/einzelthemen/1.3.4-betroffenenrechte" description="Article 16 GDPR: the data subject's right to rectification." />

  <Card title="Huber" href="/docs/dsgvo-hub/rechtsprechung/1.4.3-eugh-huber" description="CJEU C-524/06: proactive obligation to erase and rectify." />

  <Card title="Nowak" href="/docs/dsgvo-hub/rechtsprechung/1.4.8-eugh-nowak" description="CJEU C-434/16: time-related data and the limits of rectification." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.