Live Founding Cohort open, limited seats remaining Back to main site →

The seven Article 5 principles and their DPDP counterparts

Article 5 sets the seven principles of GDPR: lawfulness/fairness/transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Each is enforceable in its own right. This lesson maps each to its DPDP counterpart so you can teach one unified principle set to your organisation.

Free preview 10 min read Verified
Legal basis
GDPR primary-source stack current to 10 August 2026. Core: Regulation (EU) 2016/679 (GDPR), in force 25 May 2018. EDPB Guidelines: 3/2018 (territorial scope, endorsed 12 November 2019), 05/2020 (consent, adopted 4 May 2020 v1.1), 07/2020 (controller/processor, adopted 7 July 2021 v2.1), 9/2022 (breach notification, v2.0 adopted 28 March 2023), 1/2024 (legitimate interests, adopted 8 October 2024), draft 02/2026 (Anonymisation, published for consultation 7 July 2026), 02/2025 v2.0 (Blockchain, adopted 7 July 2026). Cross-border: Commission Implementing Decision (EU) 2021/914 SCCs (4 June 2021); EU-US Data Privacy Framework Adequacy Decision C(2023) 4745 final (10 July 2023, Latombe C-703/25 P appeal pending at CJEU); adequacy list including Brazil mutual (Implementing Decision 2026/179, 26 January 2026), UK renewal (19 December 2025 with sunset 27 December 2031). Adjacent EU: Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), Data Governance Act (Regulation 2022/868), Data Act (Regulation 2023/2854), AI Act (Regulation 2024/1689) as amended by Regulation (EU) 2026/1744 Digital Omnibus on AI (OJ 24 July 2026, in force 27 July 2026, postponing high-risk AI to 2 December 2027 and 2 August 2028), NIS2 Directive (Directive 2022/2555). Landmark CJEU: Schrems II (C-311/18, 16 Jul 2020), Meta v Bundeskartellamt (C-252/21, 4 Jul 2023), IAB Europe (C-604/22, 7 Mar 2024), Lindenapotheke (C-21/23, 4 Oct 2024). India crosswalk: DPDP Act 2023 (No. 22 of 2023, assented 11 Aug 2023), DPDP Rules 2025 (notified 13 Nov 2025, operative Rules commencement expected 13 May 2027), RBI Payment Data Storage Direction (DPSS.CO.OD.No.2785 dated 6 Apr 2018), CERT-In Directions (No. 20(3)/2022-CERT-In dated 28 Apr 2022).

Article 5(1) sets six principles of processing; Article 5(2) adds accountability as the seventh [L3-C1]. Each principle is enforceable in its own right and DPAs frequently cite the specific principle alongside the specific-provision breach. Amazon\'s EUR 746 million CNPD Luxembourg fine of 2021 rested on Art 6 legal basis but the principles of lawfulness and fairness under Art 5(1)(a) framed the reasoning. H&M\'s EUR 35.3 million HmbBfDI Hamburg fine of 2020 was for employee-monitoring processing beyond legitimate HR purpose, cited to Art 5 principles read with Art 6.

The seven principles and DPDP counterparts

GDPR Article 5Text (paraphrased)DPDP counterpart
(1)(a) Lawfulness, fairness, transparencyPersonal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.DPDP Sec 4 grounds, Sec 5 notice, Sec 6 consent standard, Rule 3 notice content [L3-C2]
(1)(b) Purpose limitationPersonal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.DPDP Sec 8(1) purpose fidelity
(1)(c) Data minimisationPersonal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.DPDP Sec 8(3) implicit via purpose limitation. GDPR wording is stronger; adopt GDPR wording as your operating standard.
(1)(d) AccuracyPersonal data shall be accurate and, where necessary, kept up to date.DPDP Sec 8(2) obligation to ensure accuracy where the personal data is likely to be used to make decisions that affect the Data Principal, or to be disclosed to another Data Fiduciary.
(1)(e) Storage limitationPersonal data shall be kept in a form which permits identification for no longer than necessary.DPDP Sec 8(7) retention duty; Rule 8 specifies retention windows for certain classes of Data Fiduciary (e-commerce, online gaming, and social-media platforms above thresholds).
(1)(f) Integrity and confidentialityPersonal data shall be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss.DPDP Sec 8(5) reasonable security safeguards; Rule 6 elaborates.
(2) AccountabilityThe controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1.DPDP Sec 8 read together; Sec 10 Rule 12 for SDFs adds explicit accountability instruments (DPIA, algorithmic-fairness audit, independent audit).

Why enforcement often cites the principle alongside the article

A DPA finding of "no valid legal basis" under Art 6 becomes stronger when framed as "no valid legal basis, therefore processing was not lawful within the meaning of Art 5(1)(a)". A finding of "excessive retention" is stronger as "excessive retention, contrary to Art 5(1)(e)". The principle framing is the DPA\'s way of saying the failure is not just technical, it is at the level of the framework\'s design intent. Practitioner implication: when your team reviews internal controls, review them against principles as well as articles. A control that satisfies Art 32 security but that leaves a footprint through Art 5(1)(f) is not a defence.

Accountability is not a slogan

The seventh principle (Art 5(2)) is the reason a DPO office exists, the reason you keep an Article 30 ROPA, the reason you run DPIAs. Accountability is the operational discipline of being able to show a supervisor how you comply. Nothing else in the Regulation reads as clearly as Art 5(2), and every subsequent article (from records under Art 30 to DPO tasks under Art 39) is a mechanism for delivering it.

DPDP\'s SDF regime (Section 10 read with Rule 12 [L3-C3]) mirrors this by requiring the SDF to appoint a DPO, run periodic DPIAs, run algorithmic-fairness audits, and undergo independent audit. For a dual-regime entity, treat the union of the two accountability regimes as your operating standard.

Practical takeaway

Post the seven principles above your privacy team\'s workspace. Every design review, every vendor onboarding, every policy refresh should be able to be traced to a principle. If you cannot say which principles a decision advances or protects, you are missing the accountability discipline of Art 5(2).

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 8 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 8 paid modules (30 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
GDPR (EU) 2016/679, Article 5 Principles (Article 5 seven data protection principles) L3-C1
Article 5(1) sets seven principles: (a) lawfulness, fairness and transparency; (b) purpose limitation; (c) data minimisation; (d) accuracy; (e) storage limitation; (f) integrity and confidentiality. Article 5(2) adds accountability: the controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1. Principles are enforceable in their own right and often cited in enforcement action alongside the specific-provision breach (Amazon €746m, H&M €35m, LinkedIn €310m).
DPDP Rules 2025, DPDP Rule 7 Breach (DPDP Rules 2025 Rule 7 breach notification) L3-C2
DPDP Rule 7 requires a Data Fiduciary to intimate the Data Protection Board of India of a personal data breach without delay and in any event within 72 hours of becoming aware of the breach, and to notify each affected Data Principal in plain-language terms without delay. Timing aligns with GDPR Art 33 72-hour clock, so a single incident record can serve both filings. Where GDPR permits a risk-based waiver of data-subject notice (Art 34(1) "unless likely to result in a high risk"), DPDP does not, so default to notify Data Principals in the dual-regime workflow.
DPDP Rules 2025, DPDP Rule 12 SDF (DPDP Rules 2025 Rule 12 Significant Data Fiduciary duties) L3-C3
DPDP Section 10 read with Rule 12 sets additional obligations for Significant Data Fiduciaries (SDFs) designated by the Central Government on factors including volume and sensitivity of personal data processed, risk to Data Principal rights, potential impact on sovereignty and integrity of India, and public order. SDF-additional obligations include appointing a Data Protection Officer based in India who reports to the Board, undertaking a periodic Data Protection Impact Assessment, an algorithmic-fairness audit for algorithmic decisions with significant impact on Data Principal rights, and independent audit by a person appointed by the SDF. Practitioner reading: SDF designation triggers a heavier compliance regime that maps closely to GDPR Art 35 DPIA plus Art 37 DPO plus general accountability.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: why GDPR reaches you as an Indian practitioner
Module 2: Lawful basis and consent
  • The six Article 6 lawful bases and why consent is overused
  • Legitimate interests: the three-part test (Guidelines 1/2024)
  • Article 7 consent standards and Guidelines 05/2020
  • Article 9 special categories and the ten Art 9(2) gateways
Module 3: Data subject rights end-to-end
  • The rights inventory and the one-month response clock
  • Article 15 access requests: the practitioner playbook
  • Article 17 erasure: six triggers, ten exceptions
  • Articles 20, 21, 22: portability, objection, automated decisions
Module 4: Controller vs processor, contracts, subprocessing
  • Determining the role: factually, not contractually
  • Article 28 processor contract: the eight mandatory clauses
  • Joint controllership under Article 26 and the transparency obligation
  • Article 30 records of processing: what an Indian processor's ROPA must show
Module 5: DPO office, DPIA, records of processing
  • Article 37 DPO trigger: when a DPO must be appointed
  • Articles 38-39: DPO independence, resources, tasks
  • Article 35 DPIA: when and how
  • One DPO office serving GDPR and DPDP in parallel
Module 6: Breach notification and the triple clock
  • Article 33: when the 72-hour clock actually starts
  • Article 34 data-subject notification: the high-risk test
  • The triple clock: CERT-In 6h, DPDP 72h, GDPR 72h
  • Worked scenario: ransomware at an Indian SaaS with EU customers
Module 7: Cross-border transfers: SCCs, adequacy, DPF, Transfer Impact Assessment
  • Chapter V architecture: adequacy, Article 46, Article 49 derogations
  • Commission SCCs 2021/914: four modules walkthrough
  • Schrems II TIA obligation: the practitioner working reference
  • EU-US Data Privacy Framework: read as fragile additional layer
  • DPDP Section 16 + Rule 15: the negative-list mirror
Module 8: Adjacent EU instruments + enforcement pattern + capstone
  • DSA, DMA, Data Act, AI Act, NIS2: what reaches an Indian entity
  • Top-15 GDPR fines 2018-2026: practitioner lessons
  • Reading the 2024-2026 enforcement pattern
  • AI Act plus GDPR for Indian AI providers: DPIA plus FRIA overlap
  • Capstone: dual-regime compliance programme for an Indian IT services firm
Module 9: Final Exam and Certificate