Article 5(1) sets six principles of processing; Article 5(2) adds accountability as the seventh [L3-C1]. Each principle is enforceable in its own right and DPAs frequently cite the specific principle alongside the specific-provision breach. Amazon\'s EUR 746 million CNPD Luxembourg fine of 2021 rested on Art 6 legal basis but the principles of lawfulness and fairness under Art 5(1)(a) framed the reasoning. H&M\'s EUR 35.3 million HmbBfDI Hamburg fine of 2020 was for employee-monitoring processing beyond legitimate HR purpose, cited to Art 5 principles read with Art 6.
The seven principles and DPDP counterparts
| GDPR Article 5 | Text (paraphrased) | DPDP counterpart |
|---|---|---|
| (1)(a) Lawfulness, fairness, transparency | Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject. | DPDP Sec 4 grounds, Sec 5 notice, Sec 6 consent standard, Rule 3 notice content [L3-C2] |
| (1)(b) Purpose limitation | Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes. | DPDP Sec 8(1) purpose fidelity |
| (1)(c) Data minimisation | Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. | DPDP Sec 8(3) implicit via purpose limitation. GDPR wording is stronger; adopt GDPR wording as your operating standard. |
| (1)(d) Accuracy | Personal data shall be accurate and, where necessary, kept up to date. | DPDP Sec 8(2) obligation to ensure accuracy where the personal data is likely to be used to make decisions that affect the Data Principal, or to be disclosed to another Data Fiduciary. |
| (1)(e) Storage limitation | Personal data shall be kept in a form which permits identification for no longer than necessary. | DPDP Sec 8(7) retention duty; Rule 8 specifies retention windows for certain classes of Data Fiduciary (e-commerce, online gaming, and social-media platforms above thresholds). |
| (1)(f) Integrity and confidentiality | Personal data shall be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss. | DPDP Sec 8(5) reasonable security safeguards; Rule 6 elaborates. |
| (2) Accountability | The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1. | DPDP Sec 8 read together; Sec 10 Rule 12 for SDFs adds explicit accountability instruments (DPIA, algorithmic-fairness audit, independent audit). |
Why enforcement often cites the principle alongside the article
A DPA finding of "no valid legal basis" under Art 6 becomes stronger when framed as "no valid legal basis, therefore processing was not lawful within the meaning of Art 5(1)(a)". A finding of "excessive retention" is stronger as "excessive retention, contrary to Art 5(1)(e)". The principle framing is the DPA\'s way of saying the failure is not just technical, it is at the level of the framework\'s design intent. Practitioner implication: when your team reviews internal controls, review them against principles as well as articles. A control that satisfies Art 32 security but that leaves a footprint through Art 5(1)(f) is not a defence.
Accountability is not a slogan
The seventh principle (Art 5(2)) is the reason a DPO office exists, the reason you keep an Article 30 ROPA, the reason you run DPIAs. Accountability is the operational discipline of being able to show a supervisor how you comply. Nothing else in the Regulation reads as clearly as Art 5(2), and every subsequent article (from records under Art 30 to DPO tasks under Art 39) is a mechanism for delivering it.
DPDP\'s SDF regime (Section 10 read with Rule 12 [L3-C3]) mirrors this by requiring the SDF to appoint a DPO, run periodic DPIAs, run algorithmic-fairness audits, and undergo independent audit. For a dual-regime entity, treat the union of the two accountability regimes as your operating standard.
Practical takeaway
Post the seven principles above your privacy team\'s workspace. Every design review, every vendor onboarding, every policy refresh should be able to be traced to a principle. If you cannot say which principles a decision advances or protects, you are missing the accountability discipline of Art 5(2).