Article 5: Principles relating to processing of personal dataAI-relevant
Praxikon tracks Article 5 (Principles relating to processing of personal data) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 5 govern?
Article 5 contains the six principles that every processing of personal data must meet: lawfulness, fairness and transparency (paragraph 1(a)), purpose limitation (b), data minimisation (c), accuracy (d), storage limitation (e) and integrity and confidentiality (f). Paragraph 2 adds accountability: the controller is responsible for compliance with those principles and must be able to demonstrate it. The article exists because the rest of the Regulation works out these principles in detail; whoever knows them understands the logic behind all the other obligations. Recital 39 explains what the principles mean in practice, such as understandable information, keeping storage to a strict minimum and setting time limits for erasure.
Key term: Accountability: the controller must not only comply with the principles but also be able to demonstrate that compliance (paragraph 2)
Directly affects:controllerprocessordata subjectdata protection officer
Praxikon’s reading of the text and the recitals; the official text below prevails.
AI Act intersection
GDPR principles (purpose limitation, minimisation, accuracy) are directly relevant for AI training data under AI Act Art. 10 (data governance).
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
Test every processing operation against the six principles of paragraph 1 and record how you meet them, because paragraph 2 requires you to be able to demonstrate compliance. Define the purpose of each processing operation in advance (paragraph 1(b)), collect no more than necessary (c) and, as recital 39 asks, set time limits for erasing data or reviewing them periodically (e). If you train an AI model on customer data, for example, the same rule applies: use only the data necessary for that purpose.
Processor
Even when you process on behalf of someone else, the data must remain accurate, secure and limited to the purpose (paragraph 1(b), (d) and (f)). Make sure you can help the controller demonstrate compliance (paragraph 2), for example by recording which security measures you have in place.
Data Protection Officer
Use the six principles as a standard test for every new project and pay particular attention to purpose limitation (paragraph 1(b)) and storage limitation (e). Check that the organisation can actually demonstrate compliance (paragraph 2) rather than merely claim it.
Data Subject
You can expect an organisation to tell you in plain language what it does with your data (paragraph 1(a) and recital 39), to collect no more than necessary and to keep your data no longer than needed. If your data are inaccurate, the organisation must take every reasonable step to erase or correct them (paragraph 1(d)).
Compliance checklist
Related recitals
Cross-references
Frequently asked questions
Connections
What connects to Article 5 GDPR
Themes where this returns
The counterpart in the other law
- Article 10 AI Act: Data and data governance
- Article 11 AI Act: Technical documentation
via Keeping records: record of processing, technical documentation and logs
- Article 12 AI Act: Record-keeping
via Keeping records: record of processing, technical documentation and logs
- Article 18 AI Act: Documentation keeping
via Keeping records: record of processing, technical documentation and logs
- Article 19 AI Act: Automatically generated logs
via Keeping records: record of processing, technical documentation and logs
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
via Keeping records: record of processing, technical documentation and logs
Case law8 of 10
- Noord-Nederland District Court upholds DPA fine for village livestream, reduces it to 375 euros
2025-01-09 · status not established, Rechtbank Noord-Nederland
- Schrems v Meta: no unlimited retention and aggregation of data for targeted advertising
2024-10-04 · final, Hof van Justitie van de EU (Vierde kamer), Maximilian Schrems tegen Meta Platforms Ireland Limited
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Mousse: asking for Mr or Ms when selling a train ticket is not necessary
2025-01-09 · final, Hof van Justitie van de EU (Eerste kamer), Mousse tegen Commission nationale de l'informatique et des libertés (CNIL) en SNCF Connect
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
- Council of State: DPA could fine DPG Media for routinely demanding ID copies, fine halved to 262,500 euros
2025-09-24 · final, Raad van State, Afdeling bestuursrechtspraak
Guidelines
- Guidelines 02/2026 on Anonymisation
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
2020-10-20 · final, European Data Protection Board (EDPB)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (legitimate interest)
2024-10-08 · adopted, European Data Protection Board (EDPB)
- Guidelines 02/2025 on processing of personal data through blockchain technologies
2026-07-07 · final, European Data Protection Board (EDPB)
- Guidelines 1/2026 on processing of personal data for scientific research purposes
2026-04-15 · adopted, European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Enforcement and fines8 of 10
- Dutch DPA and tennis federation KNLTB end litigation: fine cut from 525,000 to at most 250,000 euros
2025-10-18 · status not established, Autoriteit Persoonsgegevens
- 600,000 euro fine for AS Watson (Kruidvat) over tracking cookies without consent
2024-05-02 · annulled, Autoriteit Persoonsgegevens
- 500 euro fine and penalty order for Stichting Oud Lemmer over webcam livestream
2021-07-09 · status not established, Autoriteit Persoonsgegevens
- 100 million euro fine for MLU B.V. (Yango) for transfers to Russia
2026-04-01 · status not established, Autoriteit Persoonsgegevens
- DPA cuts Kruidvat fine to 50,000 euros on objection
2025-05-27 · status not established, Autoriteit Persoonsgegevens
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
Legislation in motion
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie