Screenata

Beyond SOC 2

What are the 7 principles of privacy?

August 18, 20263 min read

What are the 7 principles of privacy?

Two different lists carry this name. GDPR Article 5 sets out seven data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Privacy by Design, developed by Ann Cavoukian, sets out seven foundational principles for building privacy into systems. GDPR Article 5 is legally binding. Privacy by Design is a design philosophy that GDPR Article 25 partly codifies.

Which one you want depends on whether the context is legal or architectural.

GDPR Article 5: the seven data protection principles

PrincipleWhat it requires
Lawfulness, fairness, transparencyA valid legal basis, and people are told what happens to their data
Purpose limitationCollected for a stated purpose, not reused for an incompatible one
Data minimisationOnly what the purpose actually needs
AccuracyKept correct and updated, with a route to correction
Storage limitationRetained only as long as the purpose requires
Integrity and confidentialityProtected against unauthorised access, loss, and damage
AccountabilityYou can demonstrate the other six, not just satisfy them

Accountability is the one that changes daily work. It converts every other principle into something that needs a record behind it, which is why GDPR programs generate documentation the way they do.

Privacy by Design: the seven foundational principles

  1. Proactive not reactive, preventative not remedial
  2. Privacy as the default setting
  3. Privacy embedded into design
  4. Full functionality, a positive-sum rather than zero-sum outcome
  5. End-to-end security across the full data lifecycle
  6. Visibility and transparency, open to independent verification
  7. Respect for user privacy, keeping it user-centric

Developed by Ann Cavoukian while Information and Privacy Commissioner of Ontario. It is a design philosophy rather than law, though GDPR Article 25 gives part of it legal force under data protection by design and by default.

Which one to cite

SituationUse
Regulator, auditor, or DPA questionGDPR Article 5
Security questionnaire from an enterprise buyerGDPR Article 5
Engineering decisions about handling dataPrivacy by Design
Explaining your approach to customersPrivacy by Design, with Article 5 for substantiation

Citing the wrong one is not an error so much as a mismatch. A regulator asking about your principles wants Article 5. An engineer asking wants principles that survive contact with a schema design.

How this connects to SOC 2 and ISO 27001

SOC 2 has an optional Privacy trust services category, and ISO 27701 extends ISO 27001 into a privacy information management system. Neither uses either list of seven verbatim, but both test the same underlying obligations: a lawful basis, minimisation, retention limits, protection, and the ability to demonstrate all of it. Accountability is again the criterion that generates the evidence.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.