GDPR Article 5 establishes core principles that apply to all personal data processing, regardless of the specific activity or legal basis involved:
Lawfulness, fairness, and transparency
Processing must have a valid legal basis, must not deceive or harm individuals, and must be clearly communicated.
Purpose limitation
Data collected for one purpose cannot be used for an incompatible purpose without fresh consent or a new legal basis.
Data minimization
Only data that is necessary for the stated purpose should be collected.
Accuracy
Personal data must be kept accurate and up to date.
Storage limitation
Data should not be kept longer than necessary for its purpose.
Integrity and confidentiality
Appropriate security measures must protect data from unauthorized access, loss, or damage.
Accountability
Controllers must not only comply with these principles but be able to demonstrate compliance to regulators. For AI systems, purpose limitation and data minimization create specific constraints on what training data can be used and how model outputs can be applied.