CINXE.COM
Art. 5 GDPR - Principles relating to processing of personal data - GDPR.eu
<!DOCTYPE html><html lang=en-US class="no-js no-svg"><head><meta charset=UTF-8><meta name=viewport content="width=device-width, initial-scale=1.0"><link rel=profile href=http://gmpg.org/xfn/11><link type=text/css media=all href=https://gdpr.eu/wp-content/cache/autoptimize/css/autoptimize_88073fbb10b912e714cec31503f2ec90.css rel=stylesheet><title>Art. 5 GDPR - Principles relating to processing of personal data - GDPR.eu</title> <script>(function(d, s, id){ var js, fjs = d.getElementsByTagName(s)[0]; if (d.getElementById(id)) {return;} js = d.createElement(s); js.id = id; js.src = "//connect.facebook.net/en_US/sdk.js#xfbml=1&version=v2.6"; fjs.parentNode.insertBefore(js, fjs); }(document, 'script', 'facebook-jssdk'));</script> <meta name=robots content="max-snippet:-1, max-image-preview:large, max-video-preview:-1"><link rel=canonical href=https://gdpr.eu/article-5-how-to-process-personal-data/ ><meta property=og:locale content=en_US><meta property=og:type content=article><meta property=og:title content="Art. 5 GDPR - Principles relating to processing of personal data - GDPR.eu"><meta property=og:description content="Art. 5 GDPRPrinciples relating to processing of personal data Personal data shall be: processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness..."><meta property=og:url content=https://gdpr.eu/article-5-how-to-process-personal-data/ ><meta property=og:site_name content=GDPR.eu><meta property=article:tag content="Chapter 2 (Art. 5-11)"><meta property=article:tag content=GDPR><meta property=article:section content=Uncategorized><meta property=article:published_time content=2018-11-14T01:05:41+00:00><meta property=article:modified_time content=2023-09-14T15:46:42+00:00><meta property=og:updated_time content=2023-09-14T15:46:42+00:00><meta name=twitter:card content=summary_large_image><meta name=twitter:description content="Art. 5 GDPRPrinciples relating to processing of personal data Personal data shall be: processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness..."><meta name=twitter:title content="Art. 5 GDPR - Principles relating to processing of personal data - GDPR.eu"> <script type=application/ld+json class='yoast-schema-graph yoast-schema-graph--main'>{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://gdpr.eu/#organization","name":"GDPR.eu","url":"https://gdpr.eu/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https://gdpr.eu/#logo","url":"https://gdpr.eu/wp-content/uploads/2019/02/profile-pic-PH-gdpr.jpg","width":900,"height":900,"caption":"GDPR.eu"},"image":{"@id":"https://gdpr.eu/#logo"}},{"@type":"WebSite","@id":"https://gdpr.eu/#website","url":"https://gdpr.eu/","name":"GDPR.eu","publisher":{"@id":"https://gdpr.eu/#organization"},"potentialAction":{"@type":"SearchAction","target":"https://gdpr.eu/?s={search_term_string}","query-input":"required name=search_term_string"}},{"@type":"WebPage","@id":"https://gdpr.eu/article-5-how-to-process-personal-data/#webpage","url":"https://gdpr.eu/article-5-how-to-process-personal-data/","inLanguage":"en-US","name":"Art. 5 GDPR - Principles relating to processing of personal data - GDPR.eu","isPartOf":{"@id":"https://gdpr.eu/#website"},"datePublished":"2018-11-14T01:05:41+00:00","dateModified":"2023-09-14T15:46:42+00:00"},{"@type":"Article","@id":"https://gdpr.eu/article-5-how-to-process-personal-data/#article","isPartOf":{"@id":"https://gdpr.eu/article-5-how-to-process-personal-data/#webpage"},"author":{"@id":"https://gdpr.eu/#/schema/person/ea6a6cfb7b5ad33e0b774ac2085eb166"},"headline":"Art. 5 GDPR – Principles relating to processing of personal data","datePublished":"2018-11-14T01:05:41+00:00","dateModified":"2023-09-14T15:46:42+00:00","commentCount":0,"mainEntityOfPage":{"@id":"https://gdpr.eu/article-5-how-to-process-personal-data/#webpage"},"publisher":{"@id":"https://gdpr.eu/#organization"},"keywords":"Chapter 2 (Art. 5-11),GDPR","articleSection":""},{"@type":["Person"],"@id":"https://gdpr.eu/#/schema/person/ea6a6cfb7b5ad33e0b774ac2085eb166","name":"Ben Wolford","image":{"@type":"ImageObject","@id":"https://gdpr.eu/#authorlogo","url":"https://secure.gravatar.com/avatar/41724bffc3c429bc44aff458c88401e5?s=96&d=mm&r=g","caption":"Ben Wolford"},"description":"A journalist by training, Ben has reported and covered stories around the world. He joined <a href=\"https://proton.me?ref=gdpreu\">Proton</a> to help lead the fight for data privacy.","sameAs":[]}]}</script> <link rel=dns-prefetch href=//ws.sharethis.com><link rel=dns-prefetch href=//cdn.jsdelivr.net><link rel=dns-prefetch href=//maxcdn.bootstrapcdn.com><link rel=dns-prefetch href=//fonts.googleapis.com><link rel=dns-prefetch href=//use.fontawesome.com><link rel=dns-prefetch href=//s.w.org><link rel=alternate type=application/rss+xml title="GDPR.eu » Feed" href=https://gdpr.eu/feed/ ><link rel=alternate type=application/rss+xml title="GDPR.eu » Comments Feed" href=https://gdpr.eu/comments/feed/ ><link rel=alternate type=application/rss+xml title="GDPR.eu » Art. 5 GDPR – Principles relating to processing of personal data Comments Feed" href=https://gdpr.eu/article-5-how-to-process-personal-data/feed/ > <script>window._wpemojiSettings = {"baseUrl":"https:\/\/s.w.org\/images\/core\/emoji\/12.0.0-1\/72x72\/","ext":".png","svgUrl":"https:\/\/s.w.org\/images\/core\/emoji\/12.0.0-1\/svg\/","svgExt":".svg","source":{"concatemoji":"https:\/\/gdpr.eu\/wp-includes\/js\/wp-emoji-release.min.js?ver=8c03ada028d9ba4936249699216631ae"}}; !function(e,a,t){var n,r,o,i=a.createElement("canvas"),p=i.getContext&&i.getContext("2d");function s(e,t){var a=String.fromCharCode;p.clearRect(0,0,i.width,i.height),p.fillText(a.apply(this,e),0,0);e=i.toDataURL();return p.clearRect(0,0,i.width,i.height),p.fillText(a.apply(this,t),0,0),e===i.toDataURL()}function c(e){var t=a.createElement("script");t.src=e,t.defer=t.type="text/javascript",a.getElementsByTagName("head")[0].appendChild(t)}for(o=Array("flag","emoji"),t.supports={everything:!0,everythingExceptFlag:!0},r=0;r<o.length;r++)t.supports[o[r]]=function(e){if(!p||!p.fillText)return!1;switch(p.textBaseline="top",p.font="600 32px Arial",e){case"flag":return s([127987,65039,8205,9895,65039],[127987,65039,8203,9895,65039])?!1:!s([55356,56826,55356,56819],[55356,56826,8203,55356,56819])&&!s([55356,57332,56128,56423,56128,56418,56128,56421,56128,56430,56128,56423,56128,56447],[55356,57332,8203,56128,56423,8203,56128,56418,8203,56128,56421,8203,56128,56430,8203,56128,56423,8203,56128,56447]);case"emoji":return!s([55357,56424,55356,57342,8205,55358,56605,8205,55357,56424,55356,57340],[55357,56424,55356,57342,8203,55358,56605,8203,55357,56424,55356,57340])}return!1}(o[r]),t.supports.everything=t.supports.everything&&t.supports[o[r]],"flag"!==o[r]&&(t.supports.everythingExceptFlag=t.supports.everythingExceptFlag&&t.supports[o[r]]);t.supports.everythingExceptFlag=t.supports.everythingExceptFlag&&!t.supports.flag,t.DOMReady=!1,t.readyCallback=function(){t.DOMReady=!0},t.supports.everything||(n=function(){t.readyCallback()},a.addEventListener?(a.addEventListener("DOMContentLoaded",n,!1),e.addEventListener("load",n,!1)):(e.attachEvent("onload",n),a.attachEvent("onreadystatechange",function(){"complete"===a.readyState&&t.readyCallback()})),(n=t.source||{}).concatemoji?c(n.concatemoji):n.wpemoji&&n.twemoji&&(c(n.twemoji),c(n.wpemoji)))}(window,document,window._wpemojiSettings);</script> <style>img.wp-smiley, img.emoji { display: inline !important; border: none !important; box-shadow: none !important; height: 1em !important; width: 1em !important; margin: 0 .07em !important; vertical-align: -0.1em !important; background: none !important; padding: 0 !important; }</style><link rel=stylesheet id=simple-share-buttons-adder-font-awesome-css href='//maxcdn.bootstrapcdn.com/font-awesome/4.3.0/css/font-awesome.min.css?ver=8c03ada028d9ba4936249699216631ae' type=text/css media=all><link rel=stylesheet id=opensans-css href='https://fonts.googleapis.com/css?family=Open+Sans' type=text/css media=all><link rel=stylesheet id=font-awesome-css href=https://use.fontawesome.com/releases/v5.1.1/css/all.css type=text/css media=all> <script src="https://gdpr.eu/wp-content/cache/minify/c7035.js"></script> <script id=st_insights_js src='https://ws.sharethis.com/button/st_insights.js?publisher=4d48b7c5-0ae3-43d4-bfbe-3ff8c17a8ae6&product=simpleshare'></script> <link rel=https://api.w.org/ href=https://gdpr.eu/wp-json/ ><link rel=EditURI type=application/rsd+xml title=RSD href=https://gdpr.eu/xmlrpc.php?rsd><link rel=wlwmanifest type=application/wlwmanifest+xml href=https://gdpr.eu/wp-includes/wlwmanifest.xml><link rel=shortlink href='https://gdpr.eu/?p=5161'><link rel=alternate type=application/json+oembed href="https://gdpr.eu/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fgdpr.eu%2Farticle-5-how-to-process-personal-data%2F"><link rel=alternate type=text/xml+oembed href="https://gdpr.eu/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fgdpr.eu%2Farticle-5-how-to-process-personal-data%2F&format=xml"><link rel="shortcut icon" href=https://gdpr.eu/wp-content/themes/gdpr/assets/favicon.ico><link rel=apple-touch-icon sizes=57x57 href=https://gdpr.eu/wp-content/themes/gdpr/assets/apple-icon-57x57.png><link rel=apple-touch-icon sizes=60x60 href=https://gdpr.eu/wp-content/themes/gdpr/assets/apple-icon-60x60.png><link rel=apple-touch-icon sizes=72x72 href=https://gdpr.eu/wp-content/themes/gdpr/assets/apple-icon-72x72.png><link rel=apple-touch-icon sizes=76x76 href=https://gdpr.eu/wp-content/themes/gdpr/assets/apple-icon-76x76.png><link rel=apple-touch-icon sizes=114x114 href=https://gdpr.eu/wp-content/themes/gdpr/assets/apple-icon-114x114.png><link rel=apple-touch-icon sizes=120x120 href=https://gdpr.eu/wp-content/themes/gdpr/assets/apple-icon-120x120.png><link rel=apple-touch-icon sizes=144x144 href=https://gdpr.eu/wp-content/themes/gdpr/assets/apple-icon-144x144.png><link rel=apple-touch-icon sizes=152x152 href=https://gdpr.eu/wp-content/themes/gdpr/assets/apple-icon-152x152.png><link rel=apple-touch-icon sizes=180x180 href=https://gdpr.eu/wp-content/themes/gdpr/assets/apple-icon-180x180.png><link rel=icon type=image/png sizes=192x192 href=https://gdpr.eu/wp-content/themes/gdpr/assets/android-icon-192x192.png><link rel=icon type=image/png sizes=32x32 href=https://gdpr.eu/wp-content/themes/gdpr/assets/favicon-32x32.png><link rel=icon type=image/png sizes=96x96 href=https://gdpr.eu/wp-content/themes/gdpr/assets/favicon-96x96.png><link rel=icon type=image/png sizes=16x16 href=https://gdpr.eu/wp-content/themes/gdpr/assets/favicon-16x16.png><link rel=manifest href=https://gdpr.eu/wp-content/themes/gdpr/assets/manifest.json><meta name=msapplication-TileColor content=#ffffff><meta name=msapplication-TileImage content=https://gdpr.eu/wp-content/themes/gdpr/assets/ms-icon-144x144.png><meta name=theme-color content=#ffffff><style>.recentcomments a{display:inline !important;padding:0 !important;margin:0 !important;}</style></head><body class="post-template-default single single-post postid-5161 single-format-standard cookies-not-set"><div id=wrapper><header id=header><div id=social><div class="container text-right"> <a target=_blank href="http://www.facebook.com/sharer.php?u=https://gdpr.eu/"><em class="fab fa-facebook"></em> <span>Facebook</span></a> <a target=_blank href="http://twitter.com/share?url=https://gdpr.eu/"><em class="fab fa-twitter"></em> <span>Twitter</span></a></div></div><div id=top><div class=container><div class=pull-right><div class=search-box><form role=search method=get class=search-form action=https://gdpr.eu/ > <input type=search id=search-form-674b63f363eff class=textbox placeholder=Search... value name=s> <button type=submit class=button><i class=icon-search></i><span>Search</span></button></form></div></div> <span id=logo> <a href=https://gdpr.eu/ class=gdpr></a> <a target=_blank href=https://ec.europa.eu/programmes/horizon2020/en/ class=horizon></a> <img class=full src=https://gdpr.eu/wp-content/themes/gdpr/images/logo-gdpr-eu.svg alt=GDPR.eu> <img class=short src=https://gdpr.eu/wp-content/themes/gdpr/images/logo-gdpr-eu-notext.svg alt=GDPR.eu> </span></div></div><nav id=nav><div class=container><div id=searchx><div class=search-box><form role=search method=get class=search-form action=https://gdpr.eu/ > <input type=search id=search-form-674b63f363ff6 class=textbox placeholder=Search... value name=s> <button type=submit class=button><i class=icon-search></i><span>Search</span></button></form></div></div><nav id=mainmenu class=menu-primary-menu-container><ul><li id=menu-item-309 class="menu-item menu-item-type-post_type menu-item-object-page menu-item-home menu-item-309"><a href=https://gdpr.eu/ >Home</a></li><li id=menu-item-351 class="menu-item menu-item-type-post_type menu-item-object-page menu-item-351"><a href=https://gdpr.eu/checklist/ >Checklist</a></li><li id=menu-item-8150 class="menu-item menu-item-type-post_type menu-item-object-page menu-item-8150"><a href=https://gdpr.eu/faq/ >FAQ</a></li><li id=menu-item-394 class="menu-item menu-item-type-taxonomy menu-item-object-post_tag menu-item-394"><a href=https://gdpr.eu/tag/gdpr/ >GDPR</a></li><li id=menu-item-350 class="menu-item menu-item-type-taxonomy menu-item-object-category menu-item-350"><a href=https://gdpr.eu/category/news-updates/ >News & Updates</a></li></ul></nav></div></nav></header><div id=main><div id=primary class="content-area one-column"><div id=content class=site-content><div id=primary class="content-area one-column"><div class=post-main-box><div class="container section-row"><div class=post-detail-box><div class="container "><h1><p>General Data Protection Regulation (GDPR)</p></h1><div class=row><div class="col-lg-4 d-none d-xl-block"><div id=sidebar class=gdpr><section><h5><span class="d-lg-inline-block d-md-none">GDPR </span>Table of contents</h5><div class=search-box><form role=search method=get class=search-form action=https://gdpr.eu/ > <input type=search id=search-form-674b63f367e15 class=textbox placeholder="Search GDPR..." value name=s> <input type=hidden name=tag value=GDPR> <button type=submit class=button><i class=icon-search></i></button></form></div><ul><li tag-id=10 class=chapter> <span> Chapter 1 (Art. 1 – 4) <a href=https://gdpr.eu/tag/chapter-1/ ><strong><p>General provisions</p> </strong></a> <em></em> </span><ul><li data-id=5141><a href=https://gdpr.eu/article-1-subject-matter-and-objectives-overview/ >Art. 1 GDPR – Subject-matter and objectives</a></li><li data-id=5146><a href=https://gdpr.eu/article-2-processing-personal-data-by-automated-means-or-by-filling-system/ >Art. 2 GDPR – Material scope</a></li><li data-id=5151><a href=https://gdpr.eu/article-3-requirements-of-handling-personal-data-of-subjects-in-the-union/ >Art. 3 GDPR – Territorial scope</a></li><li data-id=5156><a href=https://gdpr.eu/article-4-definitions/ >Art. 4 GDPR – Definitions</a></li></ul></li></ul><ul><li tag-id=12 class=chapter> <span> Chapter 2 (Art. 5-11) <a href=https://gdpr.eu/tag/chapter-2/ ><strong><p>Principles</p> </strong></a> <em></em> </span><ul><li data-id=5161><a href=https://gdpr.eu/article-5-how-to-process-personal-data/ >Art. 5 GDPR – Principles relating to processing of personal data</a></li><li data-id=5166><a href=https://gdpr.eu/article-6-how-to-process-personal-data-legally/ >Art. 6 GDPR – Lawfulness of processing</a></li><li data-id=5171><a href=https://gdpr.eu/article-7-how-to-get-consent-to-collect-personal-data/ >Art. 7 GDPR – Conditions for consent</a></li><li data-id=5176><a href=https://gdpr.eu/article-8-childs-consent/ >Art. 8 GDPR – Conditions applicable to child’s consent in relation to information society services</a></li><li data-id=5181><a href=https://gdpr.eu/article-9-processing-special-categories-of-personal-data-prohibited/ >Art. 9 GDPR – Processing of special categories of personal data</a></li><li data-id=5186><a href=https://gdpr.eu/article-10-personal-data-relating-to-criminal-convictions-and-offences/ >Art. 10 GDPR – Processing of personal data relating to criminal convictions and offences</a></li><li data-id=5191><a href=https://gdpr.eu/article-11-what-personal-data-can-a-controller-process-without-identification/ >Art. 11 GDPR – Processing which does not require identification</a></li></ul></li></ul><ul><li tag-id=13 class=chapter> <span> Chapter 3 (Art. 12-23) <a href=https://gdpr.eu/tag/chapter-3/ ><strong><p>Rights of the data subject</p> </strong></a> <em></em> </span><ul><li data-id=5196><a href=https://gdpr.eu/article-12-how-controllers-should-provide-personal-data-to-the-subject/ >Art. 12 GDPR – Transparent information, communication and modalities for the exercise of the rights of the data subject</a></li><li data-id=5201><a href=https://gdpr.eu/article-13-personal-data-collected/ >Art. 13 GDPR – Information to be provided where personal data are collected from the data subject</a></li><li data-id=5206><a href=https://gdpr.eu/article-14-personal-data-not-obtained-from-data-subject/ >Art. 14 GDPR – Information to be provided where personal data have not been obtained from the data subject</a></li><li data-id=5211><a href=https://gdpr.eu/article-15-right-of-access/ >Art. 15 GDPR – Right of access by the data subject</a></li><li data-id=5216><a href=https://gdpr.eu/article-16-right-to-rectification/ >Art. 16 GDPR – Right to rectification</a></li><li data-id=5221><a href=https://gdpr.eu/article-17-right-to-be-forgotten/ >Art. 17 GDPR – Right to erasure (‘right to be forgotten’)</a></li><li data-id=5226><a href=https://gdpr.eu/article-18-right-to-restriction-of-processing/ >Art. 18 GDPR – Right to restriction of processing</a></li><li data-id=5231><a href=https://gdpr.eu/article-19-notification-obligation/ >Art. 19 GDPR – Notification obligation regarding rectification or erasure of personal data or restriction of processing</a></li><li data-id=5236><a href=https://gdpr.eu/article-20-right-to-data-portability/ >Art. 20 GDPR – Right to data portability</a></li><li data-id=5241><a href=https://gdpr.eu/article-21-right-to-object/ >Art. 21 GDPR – Right to object</a></li><li data-id=5246><a href=https://gdpr.eu/article-22-automated-individual-decision-making/ >Art. 22 GDPR – Automated individual decision-making, including profiling</a></li><li data-id=5251><a href=https://gdpr.eu/article-23-restrictions/ >Art. 23 GDPR – Restrictions</a></li></ul></li></ul><ul><li tag-id=14 class=chapter> <span> Chapter 4 (Art. 24-43) <a href=https://gdpr.eu/tag/chapter-4/ ><strong><p>Controller and processor</p> </strong></a> <em></em> </span><ul><li data-id=5256><a href=https://gdpr.eu/article-24-responsibility-of-the-data-controller/ >Art. 24 GDPR – Responsibility of the controller</a></li><li data-id=5261><a href=https://gdpr.eu/article-25-data-protection-by-design/ >Art. 25 GDPR – Data protection by design and by default</a></li><li data-id=5266><a href=https://gdpr.eu/article-26-joint-controllers/ >Art. 26 GDPR – Joint controllers</a></li><li data-id=5271><a href=https://gdpr.eu/article-27-representatives-of-controllers-not-in-union/ >Art. 27 GDPR – Representatives of controllers or processors not established in the Union</a></li><li data-id=5276><a href=https://gdpr.eu/article-28-processor/ >Art. 28 GDPR – Processor</a></li><li data-id=5281><a href=https://gdpr.eu/article-29-processing-under-controller-or-processor/ >Art. 29 GDPR – Processing under the authority of the controller or processor</a></li><li data-id=5286><a href=https://gdpr.eu/article-30-records-of-processing-activities/ >Art. 30 GDPR – Records of processing activities</a></li><li data-id=5291><a href=https://gdpr.eu/article-31-supervisory-authority/ >Art. 31 GDPR – Cooperation with the supervisory authority</a></li><li data-id=5296><a href=https://gdpr.eu/article-32-security-of-processing/ >Art. 32 GDPR – Security of processing</a></li><li data-id=5301><a href=https://gdpr.eu/article-33-notification-of-a-personal-data-breach/ >Art. 33 GDPR – Notification of a personal data breach to the supervisory authority</a></li><li data-id=5306><a href=https://gdpr.eu/article-34-communication-of-a-personal-data-breach/ >Art. 34 GDPR – Communication of a personal data breach to the data subject</a></li><li data-id=5311><a href=https://gdpr.eu/article-35-impact-assessment/ >Art. 35 GDPR – Data protection impact assessment</a></li><li data-id=5316><a href=https://gdpr.eu/article-36-supervisory-authority-consultation/ >Art. 36 GDPR – Prior consultation</a></li><li data-id=5321><a href=https://gdpr.eu/article-37-designation-of-the-data-protection-officer/ >Art. 37 GDPR – Designation of the data protection officer</a></li><li data-id=5326><a href=https://gdpr.eu/article-38-data-protection-officer/ >Art. 38 GDPR – Position of the data protection officer</a></li><li data-id=5331><a href=https://gdpr.eu/article-39-tasks-of-the-data-protection-officer/ >Art. 39 GDPR – Tasks of the data protection officer</a></li><li data-id=5336><a href=https://gdpr.eu/article-40-proper-application-of-the-regulation/ >Art. 40 GDPR – Codes of conduct</a></li><li data-id=5341><a href=https://gdpr.eu/article-41-approved-code-of-conduct/ >Art. 41 GDPR – Monitoring of approved codes of conduct</a></li><li data-id=5346><a href=https://gdpr.eu/article-42-data-protection-certification/ >Art. 42 GDPR – Certification</a></li><li data-id=5351><a href=https://gdpr.eu/article-43-certification-bodies/ >Art. 43 GDPR – Certification bodies</a></li></ul></li></ul><ul><li tag-id=15 class=chapter> <span> Chapter 5 (Art. 44-50) <a href=https://gdpr.eu/tag/chapter-5/ ><strong><p>Transfers of personal data to third countries or international organisations</p> </strong></a> <em></em> </span><ul><li data-id=5356><a href=https://gdpr.eu/article-44-transfer-of-personal-data/ >Art. 44 GDPR – General principle for transfers</a></li><li data-id=5361><a href=https://gdpr.eu/article-45-adequacy-decision-personal-data-transfer/ >Art. 45 GDPR – Transfers on the basis of an adequacy decision</a></li><li data-id=5366><a href=https://gdpr.eu/article-46-appropriate-safeguards-personal-data-transfers/ >Art. 46 GDPR – Transfers subject to appropriate safeguards</a></li><li data-id=5371><a href=https://gdpr.eu/article-47-binding-corporate-rules/ >Art. 47 GDPR – Binding corporate rules</a></li><li data-id=5376><a href=https://gdpr.eu/article-48-unauthorized-transfers-or-disclosures-of-personal-data/ >Art. 48 GDPR – Transfers or disclosures not authorised by Union law</a></li><li data-id=5381><a href=https://gdpr.eu/article-49-when-can-personal-data-be-transfered/ >Art. 49 GDPR – Derogations for specific situations</a></li><li data-id=5386><a href=https://gdpr.eu/article-50-countries-outside-of-europe-cooperation/ >Art. 50 GDPR – International cooperation for the protection of personal data</a></li></ul></li></ul><ul><li tag-id=16 class=chapter> <span> Chapter 6 (Art. 51-59) <a href=https://gdpr.eu/tag/chapter-6/ ><strong><p>Independent supervisory authorities</p> </strong></a> <em></em> </span><ul><li data-id=5391><a href=https://gdpr.eu/article-51-supervisory-authority-monitoring-application-of-regulation/ >Art. 51 GDPR – Supervisory authority</a></li><li data-id=5396><a href=https://gdpr.eu/article-52-supervisory-authority-independence/ >Art. 52 GDPR – Independence</a></li><li data-id=5401><a href=https://gdpr.eu/article-53-conditions-of-supervisory-authority/ >Art. 53 GDPR – General conditions for the members of the supervisory authority</a></li><li data-id=5406><a href=https://gdpr.eu/article-54-rules-on-the-establishment-of-supervisory-authority/ >Art. 54 GDPR – Rules on the establishment of the supervisory authority</a></li><li data-id=5411><a href=https://gdpr.eu/article-55-supervisory-authority-competence/ >Art. 55 GDPR – Competence</a></li><li data-id=5416><a href=https://gdpr.eu/article-56-lead-supervisory-authority-competence/ >Art. 56 GDPR – Competence of the lead supervisory authority</a></li><li data-id=5421><a href=https://gdpr.eu/article-57-supervisory-authority-tasks/ >Art. 57 GDPR – Tasks</a></li><li data-id=5426><a href=https://gdpr.eu/article-58-supervisory-authority-investigative-powers/ >Art. 58 GDPR – Powers</a></li><li data-id=5431><a href=https://gdpr.eu/article-59-supervisory-authority-activity-reports/ >Art. 59 GDPR – Activity reports</a></li></ul></li></ul><ul><li tag-id=17 class=chapter> <span> Chapter 7 (Art. 60-76) <a href=https://gdpr.eu/tag/chapter-7/ ><strong><p>Cooperation and consistency</p> </strong></a> <em></em> </span><ul><li data-id=5451><a href=https://gdpr.eu/article-63-supervisory-authority-consistency-mechanism/ >Art. 63 GDPR – Consistency mechanism</a></li><li data-id=5466><a href=https://gdpr.eu/article-66-urgent-need-determined-by-supervisory-authority/ >Art. 66 GDPR – Urgency procedure</a></li><li data-id=5471><a href=https://gdpr.eu/article-67-exchange-of-information-between-supervisory-authorities-and-board/ >Art. 67 GDPR – Exchange of information</a></li><li data-id=5461><a href=https://gdpr.eu/article-65-dispute-resolution-by-the-board/ ></a></li><li data-id=5456><a href=https://gdpr.eu/article-64-opinion-issued-by-the-board/ >Art. 64 GDPR – Opinion of the Board</a></li><li data-id=5446><a href=https://gdpr.eu/article-62-joint-operations-of-supervisory-authority/ >Art. 62 GDPR – Joint operations of supervisory authorities</a></li><li data-id=5441><a href=https://gdpr.eu/article-61-supervisory-authority-mutual-assistance/ >Art. 61 GDPR – Mutual assistance</a></li><li data-id=5436><a href=https://gdpr.eu/article-60-lead-supervisory-authority-and-other-authority-cooperation/ >Art. 60 GDPR – Cooperation between the lead supervisory authority and the other supervisory authorities concerned</a></li><li data-id=5476><a href=https://gdpr.eu/article-68-what-is-the-european-data-protection-board/ >Art. 68 GDPR – European Data Protection Board</a></li><li data-id=5481><a href=https://gdpr.eu/article-69-data-protection-board-independence/ >Art. 69 GDPR – Independence</a></li><li data-id=5486><a href=https://gdpr.eu/article-70-tasks-of-the-data-protection-board/ >Art. 70 GDPR – Tasks of the Board</a></li><li data-id=5491><a href=https://gdpr.eu/article-71-data-protection-board-annual-reports/ >Art. 71 GDPR – Reports</a></li><li data-id=5496><a href=https://gdpr.eu/article-72-data-protection-board-procedure-simple-majority-and-two-thirds-majority/ >Art. 72 GDPR – Procedure</a></li><li data-id=5501><a href=https://gdpr.eu/article-73-data-protection-board-chair-and-deputy-chair/ >Art. 73 GDPR – Chair</a></li><li data-id=5506><a href=https://gdpr.eu/article-74-tasks-of-the-data-protection-board-chair/ >Art. 74 GDPR – Tasks of the Chair</a></li><li data-id=5511><a href=https://gdpr.eu/article-75-data-protection-board-secretariat/ >Art. 75 GDPR – Secretariat</a></li><li data-id=5516><a href=https://gdpr.eu/article-76-data-protection-board-confidentiality/ >Art. 76 GDPR – Confidentiality</a></li></ul></li></ul><ul><li tag-id=19 class=chapter> <span> Chapter 8 (Art. 77-84) <a href=https://gdpr.eu/tag/chapter-8/ ><strong><p>Remedies, liability and penalties</p> </strong></a> <em></em> </span><ul><li data-id=5541><a href=https://gdpr.eu/article-81-suspension-of-duplicate-proceedings/ >Art. 81 GDPR – Suspension of proceedings</a></li><li data-id=5521><a href=https://gdpr.eu/article-77-data-subjects-right-to-lodge-a-complaint/ >Art. 77 GDPR – Right to lodge a complaint with a supervisory authority</a></li><li data-id=5526><a href=https://gdpr.eu/article-78-judicial-remedy-against-a-supervisory-authority/ >Art. 78 GDPR – Right to an effective judicial remedy against a supervisory authority</a></li><li data-id=5531><a href=https://gdpr.eu/article-79-judicial-remedy-against-a-controller-or-processor/ >Art. 79 GDPR – Right to an effective judicial remedy against a controller or processor</a></li><li data-id=5536><a href=https://gdpr.eu/article-80-representation-of-data-subjects/ >Art. 80 GDPR – Representation of data subjects</a></li><li data-id=5546><a href=https://gdpr.eu/article-82-data-subjects-right-to-compensation-and-liability/ >Art. 82 GDPR – Right to compensation and liability</a></li><li data-id=5551><a href=https://gdpr.eu/article-83-conditions-for-imposing-administrative-fines/ >Art. 83 GDPR – General conditions for imposing administrative fines</a></li><li data-id=5556><a href=https://gdpr.eu/article-84-member-state-penalties/ >Art. 84 GDPR – Penalties</a></li></ul></li></ul><ul><li tag-id=20 class=chapter> <span> Chapter 9 (Art. 85-91) <a href=https://gdpr.eu/tag/chapter-9/ ><strong><p>Provisions relating to specific processing situations</p> </strong></a> <em></em> </span><ul><li data-id=5561><a href=https://gdpr.eu/article-85-right-to-freedom-of-expression-and-information/ >Art. 85 GDPR – Processing and freedom of expression and information</a></li><li data-id=5566><a href=https://gdpr.eu/article-86-personal-data-in-official-documents/ >Art. 86 GDPR – Processing and public access to official documents</a></li><li data-id=5571><a href=https://gdpr.eu/article-87-processing-of-the-national-identification-number/ >Art. 87 GDPR – Processing of the national identification number</a></li><li data-id=5576><a href=https://gdpr.eu/article-88-processing-of-employees-personal-data/ >Art. 88 GDPR – Processing in the context of employment</a></li><li data-id=5581><a href=https://gdpr.eu/article-89-processing-for-archiving-purposes-scientific-or-historical-research-purposes-or-statistical-purposes/ >Art. 89 GDPR – Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes</a></li><li data-id=5586><a href=https://gdpr.eu/article-90-supervisory-authority-obligations-of-secrecy/ >Art. 90 GDPR – Obligations of secrecy</a></li><li data-id=5591><a href=https://gdpr.eu/article-91-data-protection-rules-of-churches-and-religious-associations/ >Art. 91 GDPR – Existing data protection rules of churches and religious associations</a></li></ul></li></ul><ul><li tag-id=21 class=chapter> <span> Chapter 10 (Art. 92-93) <a href=https://gdpr.eu/tag/chapter-10/ ><strong><p>Delegated acts and implementing acts</p> </strong></a> <em></em> </span><ul><li data-id=5596><a href=https://gdpr.eu/article-92-the-power-to-adopt-delegated-acts/ >Art. 92 GDPR – Exercise of the delegation</a></li><li data-id=5601><a href=https://gdpr.eu/article-93-committed-to-assist-the-commission/ >Art. 93 GDPR – Committee procedure</a></li></ul></li></ul><ul><li tag-id=22 class=chapter> <span> Chapter 11 (Art. 94-99) <a href=https://gdpr.eu/tag/chapter-11/ ><strong><p>Final provisions</p> </strong></a> <em></em> </span><ul><li data-id=5606><a href=https://gdpr.eu/article-94-directive-95-46-ec-repealed/ >Art. 94 GDPR – Repeal of Directive 95/46/EC</a></li><li data-id=5611><a href=https://gdpr.eu/article-95-publicly-available-electronic-communication/ >Art. 95 GDPR – Relationship with Directive 2002/58/EC</a></li><li data-id=5616><a href=https://gdpr.eu/article-96-international-agreements/ >Art. 96 GDPR – Relationship with previously concluded Agreements</a></li><li data-id=5621><a href=https://gdpr.eu/article-97-commission-reports/ >Art. 97 GDPR – Commission reports</a></li><li data-id=5626><a href=https://gdpr.eu/article-98-review-of-other-acts-on-data-protection/ >Art. 98 GDPR – Review of other Union legal acts on data protection</a></li><li data-id=5631><a href=https://gdpr.eu/article-99-start-date/ >Art. 99 GDPR – Entry into force and application</a></li></ul></li></ul></section></div></div><div class="col-xl-8 col-lg-12 single-content"><div class=gdpr-article data-id=5161> <span class=tag>12</span><span class=tag>11</span><h1 class="gdpr"><em>Art. 5 GDPR</em><strong>Principles relating to processing of personal data</strong></h1><ol><li>Personal data shall be:<ol><li>processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);</li><li>collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with <a href=https://gdpr.eu/article-89-processing-for-archiving-purposes-scientific-or-historical-research-purposes-or-statistical-purposes>Article 89</a>(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);</li><li>adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);</li><li>accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);</li><li>kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with <a href=https://gdpr.eu/article-89-processing-for-archiving-purposes-scientific-or-historical-research-purposes-or-statistical-purposes>Article 89(</a>1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);</li><li>processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).</li></ol></li><li>The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).</li></ol><div class=suitable-recitals><h2>Suitable Recitals</h2><p> <br> <span><a href=https://gdpr.eu/Recital-39-Principles-of-data-processing>(<span class=bold-number>39</span>) Principles of data processing</a></span></div><div class=page-navigation><div class=alignleft> <a href=https://gdpr.eu/article-4-definitions title="Art. 4 GDPR - Definitions"><span class=previous-page>←</span>Art. 4 GDPR</a></div><div class=alignright> <a href=https://gdpr.eu/article-6-how-to-process-personal-data-legally title="Art. 6 GDPR - Lawfulness of processing">Art. 6 GDPR<span class=next-page>→</span></a></div></p></div><p></p></div><div class=rp4wp-related-posts><h3>Related Posts</h3><ul><li><div class=rp4wp-related-post-content> <a href=https://gdpr.eu/article-20-right-to-data-portability/ >Art. 20 GDPR - Right to data portability</a></div></li><li><div class=rp4wp-related-post-content> <a href=https://gdpr.eu/article-10-personal-data-relating-to-criminal-convictions-and-offences/ >Art. 10 GDPR - Processing of personal data relating to criminal convictions and offences</a></div></li><li><div class=rp4wp-related-post-content> <a href=https://gdpr.eu/article-6-how-to-process-personal-data-legally/ >Art. 6 GDPR - Lawfulness of processing</a></div></li></ul></div></div></div></div></div></div></div></div></div></div></div></div><footer id=footer><div class=container><div class=post-author-details-box><div class=post-author-details><h6>About GDPR.EU</h6><p> </p><p>GDPR.EU is a website operated by Proton Technologies AG, which is co-funded by Project REP-791727-1 of the Horizon 2020 Framework Programme of the European Union. This is not an official EU Commission or Government resource. The europa.eu webpage concerning GDPR can be found <a href=https://ec.europa.eu/commission/priorities/justice-and-fundamental-rights/data-protection/2018-reform-eu-data-protection-rules_en target=_blank>here</a>. Nothing found in this portal constitutes legal advice.</p></div></div><div class=footer-top><div class=row><div class=col-sm-3> <br><h5>Getting Started</h5><br><div class=menu-deep-footer-column-1-container><ul class=fmenu><li id=menu-item-9315 class="menu-item menu-item-type-post_type menu-item-object-post menu-item-9315"><a href=https://gdpr.eu/what-is-gdpr/ >What is GDPR?</a></li><li id=menu-item-9316 class="menu-item menu-item-type-post_type menu-item-object-post menu-item-9316"><a href=https://gdpr.eu/fines/ >What are the GDPR Fines?</a></li><li id=menu-item-9317 class="menu-item menu-item-type-post_type menu-item-object-page menu-item-9317"><a href=https://gdpr.eu/checklist/ >GDPR Compliance Checklist</a></li></ul></div></div><div class=col-sm-3> <br><h5>Templates</h5><br><div class=menu-deep-footer-column-2-container><ul class=fmenu><li id=menu-item-9318 class="menu-item menu-item-type-post_type menu-item-object-post menu-item-9318"><a href=https://gdpr.eu/data-processing-agreement/ >Data Processing Agreement</a></li><li id=menu-item-9319 class="menu-item menu-item-type-post_type menu-item-object-post menu-item-9319"><a href=https://gdpr.eu/right-to-erasure-request-form/ >Right to Erasure Request Form</a></li><li id=menu-item-9320 class="menu-item menu-item-type-post_type menu-item-object-post menu-item-9320"><a href=https://gdpr.eu/privacy-notice/ >Writing a GDPR-compliant privacy notice</a></li></ul></div></div><div class=col-sm-3> <br><h5>Technical Review</h5><br><div class=menu-deep-footer-column-3-container><ul class=fmenu><li id=menu-item-9321 class="menu-item menu-item-type-post_type menu-item-object-post menu-item-9321"><a href=https://gdpr.eu/data-protection-officer/ >Data Protection Office Guide</a></li><li id=menu-item-9322 class="menu-item menu-item-type-post_type menu-item-object-post menu-item-9322"><a href=https://gdpr.eu/email-encryption/ >GDPR and Email</a></li><li id=menu-item-9323 class="menu-item menu-item-type-post_type menu-item-object-post menu-item-9323"><a href=https://gdpr.eu/companies-outside-of-europe/ >Does GDPR apply outside of the EU</a></li></ul></div></div><div class=col-sm-3> <br><h5>About Us</h5><br><p>GDPR.eu is co-funded by the <a href=https://ec.europa.eu/programmes/horizon2020/en/ >Horizon 2020</a> Framework Programme of the European Union <strong>and operated by Proton AG</strong>.</p></div></div></div><div class=formz><p> </p><p><strong>GDPR Forms and Templates</strong></p><p> <a href=/data-processing-agreement/ ><i class="far fa-file-alt"></i> <strong>Data Processing Agreement</strong> <i class="fa fa-chevron-right"></i></a> <a href=/right-to-erasure-request-form/ ><i class="far fa-file-alt"></i> <strong>Right to Erasure Request Form</strong> <i class="fa fa-chevron-right"></i></a> <a href=/privacy-notice/ ><i class="far fa-file-alt"></i> <strong>Privacy Policy</strong> <i class="fa fa-chevron-right"></i></a></p></div><p> </p><p class=copyright>© 2024 Proton AG. All Rights Reserved.</p><p class=text-center> <br> <a href=https://gdpr.eu/terms-and-conditions/ >Terms and Conditions</a> <a href=https://gdpr.eu/privacy-policy/ >Privacy Policy</a></p></div></footer></div><div id=compliance_a style=display:none;> <a href=# class="close fa fa-times"></a> <img src=https://gdpr.eu/wp-content/themes/gdpr/images/gdpr_graphic.svg alt="GDPR Graphic"><p>GDPR compliance is easier with <strong>encrypted email</strong></p> <span><a target=_blank href="https://proton.me/business/gdpr?ref=gdpreu">Learn more <i class="fa fa-chevron-right"></i></a></span></div> <script>var cnArgs = {"ajaxurl":"https:\/\/gdpr.eu\/wp-admin\/admin-ajax.php","hideEffect":"fade","onScroll":"no","onScrollOffset":"100","cookieName":"cookie_notice_accepted","cookieValue":"true","cookieTime":"2592000","cookiePath":"\/","cookieDomain":"","redirection":"1","cache":"1","refuse":"yes","revoke_cookies":"0","revoke_cookies_opt":"automatic","secure":"1"};</script> <script src="https://gdpr.eu/wp-content/cache/minify/6fdea.js"></script> <script>Main.boot( [] );</script> <script src=https://cdn.jsdelivr.net/npm/js-cookie@2/src/js.cookie.min.js></script> <div id=cookie-notice role=banner class="cn-bottom bootstrap" style="color: #fff; background-color: #000;" aria-label="Cookie Notice"><div class=cookie-notice-container><span id=cn-notice-text>We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.</span><a href=# id=cn-accept-cookie data-cookie-set=accept class="cn-set-cookie cn-button bootstrap button">Ok</a><a href=# id=cn-refuse-cookie data-cookie-set=refuse class="cn-set-cookie cn-button bootstrap button">No</a><a href=https://gdpr.eu/privacy-policy/ target=_blank id=cn-more-info class="cn-more-info cn-button bootstrap button">Privacy policy</a></div><div class=cookie-notice-revoke-container><a href=# class="cn-revoke-cookie cn-button bootstrap button">Revoke cookies</a></div></div> <script defer src=https://gdpr.eu/wp-content/cache/autoptimize/js/autoptimize_5dd90da4735596921829dacc461fe36f.js></script></body></html> <!-- Performance optimized by W3 Total Cache. Learn more: https://www.w3-edge.com/products/ Page Caching using disk: enhanced Minified using disk Database Caching 63/145 queries in 0.063 seconds using disk Served from: gdpr.eu @ 2024-11-30 20:13:55 by W3 Total Cache -->