Beyond SOC 2
What are the 7 data policy principles?
What are the 7 data policy principles?
The 7 data policy principles are the data protection principles in Article 5 of the GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Every use of personal data about people in the EU or UK must satisfy all seven. Breaching them is the most serious tier of GDPR infringement, carrying fines of up to 20 million euros or 4% of global annual turnover, whichever is higher.
The seven principles, and how each one fails
| Principle | What it requires | How it fails |
|---|---|---|
| Lawfulness, fairness and transparency | A valid legal basis for processing, and telling people what you do with their data | Collecting data under a privacy policy nobody could understand, or with no legal basis identified at all |
| Purpose limitation | Use data only for the purposes you collected it for | Support emails quietly reused to train a model or feed a marketing list |
| Data minimisation | Collect only what the purpose actually needs | A signup form demanding date of birth and phone number for a newsletter |
| Accuracy | Keep personal data correct and up to date | Decisions made on stale records with no way for people to correct them |
| Storage limitation | Keep data no longer than the purpose requires | No retention schedule; every record kept forever by default |
| Integrity and confidentiality | Protect data with appropriate security | A breach traced to an unencrypted export or an access control nobody reviewed |
| Accountability | Be able to demonstrate compliance with the other six | Practices may even be fine, but nothing is documented, so nothing can be proven |
Which list of principles you actually mean
Three similar-sounding lists circulate, and search results blend them. Resolving which one you need matters because only one of them is current law.
The 7 GDPR principles (this page) are Article 5 of the EU GDPR, in force since 25 May 2018, and mirrored in the UK GDPR. This is what "the 7 principles of data protection" means today.
The 8 principles of the Data Protection Act 1998 were the previous UK regime. The list overlaps heavily but has eight entries, including a standalone principle on international transfers. The 1998 Act was repealed when GDPR took effect, so an eight-item list is a sign the source is out of date.
The 7 foundational principles of Privacy by Design come from Ann Cavoukian's 1990s framework: proactive not reactive, privacy as the default setting, privacy embedded into design, and so on. It is a design philosophy, not legislation. GDPR adopted the concept in Article 25 as data protection by design and by default, which is why the two get merged in casual usage, but the seven Cavoukian principles are not the seven Article 5 principles.
Accountability is the one that generates the paperwork
Six of the principles describe how data should be handled. Accountability is different: it requires you to be able to demonstrate compliance with the other six. That single word is where most GDPR paperwork originates. Records of processing activities under Article 30, data processing agreements with every vendor that touches personal data, a privacy policy that matches reality, retention schedules, and data protection impact assessments for higher-risk processing all exist to satisfy accountability.
This is also why a company can follow the first six principles in practice and still be exposed. A regulator investigating a complaint asks for the documentation first. If minimisation and storage limitation are genuinely observed but never written down, there is no evidence to show, and accountability is itself breached.
For teams that already run a security compliance program, the useful framing is that the GDPR principles behave like control objectives: each one implies documents, decisions, and records that must exist and stay current, and the demonstration matters as much as the practice.