CIPP/E Study Guide
IAPP Training · Module 4 - BoK III.B

Module 4 · Data processing principles (OECD + Article 5)

The GDPR's Article 5 principles - lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality and accountability - sit on top of the eight OECD principles. Breaching them can attract the highest-tier fines.

The eight OECD principles are: collection limitation, data quality, purpose specification, use limitation, openness, individual participation, accountability and security safeguards. The GDPR builds on them in Article 5.

The Article 5 principles
PrincipleWhat it requires
Lawfulness, fairness and transparencyProcess on a lawful basis, fairly, and openly
Purpose limitationCollect for a specified purpose only; further use must pass a compatibility test (links between purposes, nature of data, method of collection, consequences, safeguards)
Data minimisationOnly data that is relevant and necessary
AccuracyKeep data complete and up to date
Storage limitationRetain only as long as necessary for the original purpose
Integrity and confidentialityProcess securely
AccountabilityBe able to demonstrate compliance
Exam trap - the compatibility test

Further processing is allowed where it is not incompatible with the original purpose. The purpose limitation compatibility test weighs the link between purposes, the nature of the data, the method of collection, the consequences, and the safeguards in place.

Related EU laws to know: PSD2 (EDPB Guidelines 06/2020 on the PSD2/GDPR interplay), the Data Governance Act, Regulation (EU) 2018/1725 (covering EU institutions), and the EU Data Act.

Key terms - quick answers

What is “Article 5”?
The GDPR provision setting out the seven data processing principles plus accountability.
What is “OECD principles”?
Eight foundational data principles: collection limitation, data quality, purpose specification, use limitation, openness, individual participation, accountability, security safeguards.
What is “Purpose limitation”?
Data collected for a specified purpose may not be further processed in an incompatible way; a compatibility test governs further use.
What is “Data minimisation”?
Only data that is relevant and necessary for the purpose may be processed.