<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What are the 7 data policy principles?"
title: "What Are the 7 Data Policy Principles"
seoTitle: "7 Data Protection Principles of GDPR Explained"
summary: "The 7 data policy principles almost always refer to Article 5 of the GDPR: (1) lawfulness, fairness and transparency, (2) purpose limitation, (3) data minimisation, (4) accuracy, (5) storage limitation, (6) integrity and confidentiality (security), and (7) accountability. They govern all processing of personal data about people in the EU and UK, and breaching them carries fines of up to 20 million euros or 4% of global annual turnover, whichever is higher. The list is often called the 7 principles of data protection and is distinct from two lists people mix it up with: the 8 principles of the old UK Data Protection Act 1998, and the 7 foundational principles of Privacy by Design."
publishedAt: "2026-08-22"
keywords:
  - "7 data policy principles"
  - "7 principles of data protection"
  - "GDPR Article 5 principles"
  - "GDPR data processing principles"
pillar: "Beyond SOC 2"
faqs:
  - question: "What are the 7 principles of GDPR?"
    answer: "The seven principles in Article 5 of the GDPR are lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability. Every processing activity involving personal data must satisfy all seven. Accountability is the meta-principle: it requires you to be able to demonstrate compliance with the other six, which is where records of processing, DPAs, and policies come from."
  - question: "What is the difference between GDPR principles and Privacy by Design?"
    answer: "The GDPR principles are binding law: seven rules in Article 5 that all processing of personal data must follow. Privacy by Design is a design philosophy with its own seven foundational principles, written by Ann Cavoukian in the 1990s, such as privacy as the default setting and end-to-end security. GDPR absorbed the idea as the Article 25 obligation of data protection by design and by default, but the two seven-item lists are different lists."
  - question: "Do the 7 principles apply to US companies?"
    answer: "Yes, if the company processes personal data of people in the EU or UK, for example by offering them goods or services or monitoring their behavior. GDPR applies based on whose data is processed, not where the company is incorporated. A US SaaS company with European users is in scope and is expected to meet all seven principles, usually formalized through a privacy policy, records of processing, and data processing agreements with its vendors."
  - question: "What are the 7 data protection principles?"
    answer: "The 7 data protection principles are the GDPR Article 5 principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The phrases 7 data policy principles, 7 data protection principles, and 7 principles of GDPR all refer to this same list. Every processing of personal data about people in the EU or UK must satisfy all seven."
  - question: "What is the main difference between GDPR and CCPA?"
    answer: "GDPR requires a lawful basis before any processing of personal data happens, while the CCPA (as amended by the CPRA) is an opt-out regime: California businesses may generally process personal information but must honor consumer rights such as opting out of sale or sharing. Scope differs too: GDPR covers essentially all organizations processing EU or UK personal data, while CCPA applies to for-profit businesses over thresholds such as $25 million in annual revenue. GDPR fines scale to 4% of global turnover; CCPA penalties are set per violation."
  - question: "Can GDPR be enforced in the US?"
    answer: "In practice, yes against companies with an EU establishment, EU revenue, or EU-based assets, since regulators can reach those directly. A pure US company with no EU presence is hard for an EU regulator to reach, and cross-border enforcement of fines is untested. The pressure usually arrives commercially instead: EU customers and partners require GDPR compliance by contract, typically through a data processing agreement, so the obligations bind US vendors regardless of enforcement mechanics."
---

## What are the 7 data policy principles?

The 7 data policy principles are the data protection principles in **Article 5 of the GDPR**: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Every use of personal data about people in the EU or UK must satisfy all seven. Breaching them is the most serious tier of GDPR infringement, carrying fines of up to 20 million euros or 4% of global annual turnover, whichever is higher.

## The seven principles, and how each one fails

| Principle | What it requires | How it fails |
|---|---|---|
| Lawfulness, fairness and transparency | A valid legal basis for processing, and telling people what you do with their data | Collecting data under a privacy policy nobody could understand, or with no legal basis identified at all |
| Purpose limitation | Use data only for the purposes you collected it for | Support emails quietly reused to train a model or feed a marketing list |
| Data minimisation | Collect only what the purpose actually needs | A signup form demanding date of birth and phone number for a newsletter |
| Accuracy | Keep personal data correct and up to date | Decisions made on stale records with no way for people to correct them |
| Storage limitation | Keep data no longer than the purpose requires | No retention schedule; every record kept forever by default |
| Integrity and confidentiality | Protect data with appropriate security | A breach traced to an unencrypted export or an access control nobody reviewed |
| Accountability | Be able to demonstrate compliance with the other six | Practices may even be fine, but nothing is documented, so nothing can be proven |

## Which list of principles you actually mean

Three similar-sounding lists circulate, and search results blend them. Resolving which one you need matters because only one of them is current law.

**The 7 GDPR principles** (this page) are Article 5 of the EU GDPR, in force since 25 May 2018, and mirrored in the UK GDPR. This is what "the 7 principles of data protection" means today.

**The 8 principles of the Data Protection Act 1998** were the previous UK regime. The list overlaps heavily but has eight entries, including a standalone principle on international transfers. The 1998 Act was repealed when GDPR took effect, so an eight-item list is a sign the source is out of date.

**The 7 foundational principles of Privacy by Design** come from Ann Cavoukian's 1990s framework: proactive not reactive, privacy as the default setting, privacy embedded into design, and so on. It is a design philosophy, not legislation. GDPR adopted the concept in Article 25 as data protection by design and by default, which is why the two get merged in casual usage, but the seven Cavoukian principles are not the seven Article 5 principles.

## Accountability is the one that generates the paperwork

Six of the principles describe how data should be handled. Accountability is different: it requires you to be able to **demonstrate** compliance with the other six. That single word is where most GDPR paperwork originates. Records of processing activities under Article 30, data processing agreements with every vendor that touches personal data, a privacy policy that matches reality, retention schedules, and data protection impact assessments for higher-risk processing all exist to satisfy accountability.

This is also why a company can follow the first six principles in practice and still be exposed. A regulator investigating a complaint asks for the documentation first. If minimisation and storage limitation are genuinely observed but never written down, there is no evidence to show, and accountability is itself breached.

For teams that already run a security compliance program, the useful framing is that the GDPR principles behave like control objectives: each one implies documents, decisions, and records that must exist and stay current, and the demonstration matters as much as the practice.
