GDPR Privacy Principles
The GDPR codifies these concepts of privacy (in its Article 5) into six broad principles regarding the use of personal data.
3 slides · 1 min read · Domain 1
LAWFULNESS, FAIRNESS AND TRANSPARENCY
Data must be collected, processed, used, shared, stored, and destroyed in ways that are legal, fair, and transparent (that is, subject to review and audit), with respect to the data subject.
DATA MINIMIZATION
Data collection, generation, and use must be limited to the minimum amount of data necessary for the specified purpose.
PURPOSE LIMITATION
Collected and processed for specified, explicit and legitimate purposes, which may include follow-on analytical, archival, statistical, scientific or historical research purposes that are in the public interest.
ACCURACY
Data must be collected, created, stored, and used in ways that maintain its accuracy with respect to the data subject. There must also be reasonable steps taken to allow data subjects to review data held regarding them and submit requests for it to be corrected.
STORAGE LIMITATION
Data should not be kept longer than is necessary for its legitimate and fair use (unless such retention supports follow-on analysis or research in the public interest).
INTEGRITY AND CONFIDENTIALITY
Data must be processed, stored, or transported in ways that ensure its protection against unauthorized viewing, use, copying, or modification; these also include the ultimate destruction of the data at the end of its specified useful life.
