The 7 Principles of GDPR (Article 5)
1. Lawfulness, Fairness and Transparency
Personal data must be processed on a valid legal basis (such as consent, contract, or legitimate interest), in ways people would reasonably expect, and organizations must be clear about what they're doing with the data and why.
2. Purpose Limitation
Data can only be collected for specified, explicit, and legitimate purposes — and can't later be reused for a materially different purpose without a new legal basis.
3. Data Minimisation
Only the data that's actually necessary for the stated purpose should be collected — not data that might be useful someday.
4. Accuracy
Personal data must be kept accurate and, where necessary, kept up to date; inaccurate data should be corrected or erased without undue delay.
5. Storage Limitation
Data shouldn't be kept in an identifiable form for longer than necessary for the purpose it was collected for — this is why most privacy policies specify retention periods.
6. Integrity and Confidentiality (Security)
Organizations must use appropriate technical and organizational measures (encryption, access controls, etc.) to protect data against unauthorized access, loss, or destruction.
7. Accountability
Added in Article 5(2): the data controller is responsible for complying with all six principles above and must be able to demonstrate that compliance — through documentation, records of processing, and policies — not just claim it.
Why You'll See Different Numbers Elsewhere
Content citing "4," "5," "6," or "12 principles of GDPR" is usually doing one of two things: describing only part of Article 5 (e.g., leaving out accountability, which gets its own paragraph in 5(2) and is sometimes missed), or conflating principles with separate GDPR concepts — like the 8 individual data-subject rights (access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making), which are a different part of the regulation entirely (Chapter III), not "principles."
Frequently Asked Questions
Is purpose limitation one of the 7 principles?
Yes — it's principle 2 in Article 5(1)(b).
What's the difference between GDPR principles and GDPR rights?
Principles (Article 5) govern how organizations must handle data in general. Rights (Chapter III) are specific entitlements individuals can exercise, like requesting a copy of their data or asking for it to be deleted.
Are all 7 principles equally enforced?
Regulators can act on a breach of any single principle, but accountability is often central to enforcement outcomes, since it determines whether an organization can prove it was compliant in the first place.
The Bottom Line
If you need the authoritative count: it's 7, straight from Article 5 of the regulation itself. Any other number you encounter is either incomplete or describing something else.