GDPR principles

GDPR Article 5 establishes core principles that apply to all personal data processing, regardless of the specific activity or legal basis involved:

Lawfulness, fairness, and transparency

Processing must have a valid legal basis, must not deceive or harm individuals, and must be clearly communicated.

Purpose limitation

Data collected for one purpose cannot be used for an incompatible purpose without fresh consent or a new legal basis.

Data minimization

Only data that is necessary for the stated purpose should be collected.

Accuracy

Personal data must be kept accurate and up to date.

Storage limitation

Data should not be kept longer than necessary for its purpose.

Integrity and confidentiality

Appropriate security measures must protect data from unauthorized access, loss, or damage.

Accountability

Controllers must not only comply with these principles but be able to demonstrate compliance to regulators. For AI systems, purpose limitation and data minimization create specific constraints on what training data can be used and how model outputs can be applied.