EU regulatory register · GDPR
Article 5Principles relating to processing of personal data
CELEX 32016R0679 · Read on 2026-08-18 · Chapter II
Official text
Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.
1. Personal data shall be:
(a)
processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
(b)
collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
(c)
adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);
(d)
accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
(e)
kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);
(f)
processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).
2. The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).
Other articles in this chapter
Judgments of the Court of Justice
8 decisions
- C-247/23Court of Justice of the European Union
VP v Országos Idegenrendészeti Főigazgatóság
Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(d) – Principle of accuracy – Article 16 – Right to rectification – Article 23 – Restrictions – Data relating to gender identity – Data incorrect from the time of inclusion in a public register – Means of proof – Administrative practice of requesting proof of gender reassignment surgery.
- C-394/23Court of Justice of the European Union
Mousse v Commission nationale de l'informatique et des libertés (CNIL) and SNCF Connect
Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(c) – Data minimisation – Article 6(1) – Lawfulness of processing – Data relating to title and gender identity – Online sale of travel documents – Article 21 – Right to object.
- C-65/23Court of Justice of the European Union
MK v K GmbH
Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6(1) and Article 9(1) and (2) of that regulation – Processing on the basis of a collective agreement – Margin of discretion of the parties to the collective agreement as regards the necessity of the processing of personal data provided for by that agreement – Scope of judicial review.
- C-446/21Court of Justice of the European Union
Maximilian Schrems v Meta Platforms Ireland Limited
Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpose limitation – Article 5(1)(c) – Principle of data minimisation – Article 9(1) and (2) – Processing of special categories of personal data – Data concerning sexual orientation – Data which are made public by the data subject.
- C-621/22Court of Justice of the European Union
Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens
Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Lawfulness of processing – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interests pursued by the controller or by a third party – Concept of ‘legitimate interests’ – Commercial interest – Sports federation – Disclosure, for consideration, of the personal data of the members of a sports federation to sponsors without the consent of those members.
- C-687/21Court of Justice of the European Union
BL v MediaMarktSaturn Hagen-Iserlohn GmbH
Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Interpretation of Articles 5, 24, 32 and 82 – Assessment of the validity of Article 82 – Inadmissibility of the request for an assessment of validity – Right to compensation for damage caused by data processing which infringes that regulation – Transmission of data to an unauthorised third party on account of an error made by the employees of the controller – Assessment of the appropriateness of the protection measures implemented by the controller – Compensatory function fulfilled by the right to compensation – Effect of the severity of the infringement – Whether necessary to establish the existence of damage caused by that infringement – Concept of ‘non-material damage’.
- C-231/22Court of Justice of the European Union
État belge v Autorité de protection des données
Reference for a preliminary ruling – Approximation of laws – Protection of natural persons with regard to the processing of personal data and free movement of such data (General Data Protection Regulation) – Regulation (EU) 2016/679 – Point 7 of Article 4 – Concept of ‘controller’ – Official journal of a Member State – Obligation to publish as they stand company documents prepared by companies or their legal representatives – Article 5(2) – Successive processing of the personal data contained in such documents by several separate persons or entities – Determination of responsibilities.
- C-340/21Court of Justice of the European Union
VB v Natsionalna agentsia za prihodite
Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to that processing – Article 24 – Accountability of the controller – Article 32 – Measures implemented to ensure security of processing – Assessment of the appropriateness of such measures – Scope of judicial review – Taking of evidence – Article 82 – Right to compensation and liability – Possible exemption from liability of the controller in the event of infringement by third parties – Claim for compensation for non-material damage based on fear of potential misuse of personal data.
The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act