Beyond SOC 2
What are the 7 principles of privacy?
What are the 7 principles of privacy?
Two different lists carry this name. GDPR Article 5 sets out seven data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Privacy by Design, developed by Ann Cavoukian, sets out seven foundational principles for building privacy into systems. GDPR Article 5 is legally binding. Privacy by Design is a design philosophy that GDPR Article 25 partly codifies.
Which one you want depends on whether the context is legal or architectural.
GDPR Article 5: the seven data protection principles
| Principle | What it requires |
|---|---|
| Lawfulness, fairness, transparency | A valid legal basis, and people are told what happens to their data |
| Purpose limitation | Collected for a stated purpose, not reused for an incompatible one |
| Data minimisation | Only what the purpose actually needs |
| Accuracy | Kept correct and updated, with a route to correction |
| Storage limitation | Retained only as long as the purpose requires |
| Integrity and confidentiality | Protected against unauthorised access, loss, and damage |
| Accountability | You can demonstrate the other six, not just satisfy them |
Accountability is the one that changes daily work. It converts every other principle into something that needs a record behind it, which is why GDPR programs generate documentation the way they do.
Privacy by Design: the seven foundational principles
- Proactive not reactive, preventative not remedial
- Privacy as the default setting
- Privacy embedded into design
- Full functionality, a positive-sum rather than zero-sum outcome
- End-to-end security across the full data lifecycle
- Visibility and transparency, open to independent verification
- Respect for user privacy, keeping it user-centric
Developed by Ann Cavoukian while Information and Privacy Commissioner of Ontario. It is a design philosophy rather than law, though GDPR Article 25 gives part of it legal force under data protection by design and by default.
Which one to cite
| Situation | Use |
|---|---|
| Regulator, auditor, or DPA question | GDPR Article 5 |
| Security questionnaire from an enterprise buyer | GDPR Article 5 |
| Engineering decisions about handling data | Privacy by Design |
| Explaining your approach to customers | Privacy by Design, with Article 5 for substantiation |
Citing the wrong one is not an error so much as a mismatch. A regulator asking about your principles wants Article 5. An engineer asking wants principles that survive contact with a schema design.
How this connects to SOC 2 and ISO 27001
SOC 2 has an optional Privacy trust services category, and ISO 27701 extends ISO 27001 into a privacy information management system. Neither uses either list of seven verbatim, but both test the same underlying obligations: a lawful basis, minimisation, retention limits, protection, and the ability to demonstrate all of it. Accountability is again the criterion that generates the evidence.