Screenata

Beyond SOC 2

What are the 7 data policy principles?

August 22, 20263 min read

What are the 7 data policy principles?

The 7 data policy principles are the data protection principles in Article 5 of the GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Every use of personal data about people in the EU or UK must satisfy all seven. Breaching them is the most serious tier of GDPR infringement, carrying fines of up to 20 million euros or 4% of global annual turnover, whichever is higher.

The seven principles, and how each one fails

PrincipleWhat it requiresHow it fails
Lawfulness, fairness and transparencyA valid legal basis for processing, and telling people what you do with their dataCollecting data under a privacy policy nobody could understand, or with no legal basis identified at all
Purpose limitationUse data only for the purposes you collected it forSupport emails quietly reused to train a model or feed a marketing list
Data minimisationCollect only what the purpose actually needsA signup form demanding date of birth and phone number for a newsletter
AccuracyKeep personal data correct and up to dateDecisions made on stale records with no way for people to correct them
Storage limitationKeep data no longer than the purpose requiresNo retention schedule; every record kept forever by default
Integrity and confidentialityProtect data with appropriate securityA breach traced to an unencrypted export or an access control nobody reviewed
AccountabilityBe able to demonstrate compliance with the other sixPractices may even be fine, but nothing is documented, so nothing can be proven

Which list of principles you actually mean

Three similar-sounding lists circulate, and search results blend them. Resolving which one you need matters because only one of them is current law.

The 7 GDPR principles (this page) are Article 5 of the EU GDPR, in force since 25 May 2018, and mirrored in the UK GDPR. This is what "the 7 principles of data protection" means today.

The 8 principles of the Data Protection Act 1998 were the previous UK regime. The list overlaps heavily but has eight entries, including a standalone principle on international transfers. The 1998 Act was repealed when GDPR took effect, so an eight-item list is a sign the source is out of date.

The 7 foundational principles of Privacy by Design come from Ann Cavoukian's 1990s framework: proactive not reactive, privacy as the default setting, privacy embedded into design, and so on. It is a design philosophy, not legislation. GDPR adopted the concept in Article 25 as data protection by design and by default, which is why the two get merged in casual usage, but the seven Cavoukian principles are not the seven Article 5 principles.

Accountability is the one that generates the paperwork

Six of the principles describe how data should be handled. Accountability is different: it requires you to be able to demonstrate compliance with the other six. That single word is where most GDPR paperwork originates. Records of processing activities under Article 30, data processing agreements with every vendor that touches personal data, a privacy policy that matches reality, retention schedules, and data protection impact assessments for higher-risk processing all exist to satisfy accountability.

This is also why a company can follow the first six principles in practice and still be exposed. A regulator investigating a complaint asks for the documentation first. If minimisation and storage limitation are genuinely observed but never written down, there is no evidence to show, and accountability is itself breached.

For teams that already run a security compliance program, the useful framing is that the GDPR principles behave like control objectives: each one implies documents, decisions, and records that must exist and stay current, and the demonstration matters as much as the practice.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.