GDPR Principles

Information Commissioner's Office framework for GDPR compliance, providing principles for lawful, fair, and transparent data processing while protecting individual privacy rights.

  1. Lawfulness, fairness and transparency

    Data should be processed lawfully, fairly and in a transparent manner.

  2. Purpose limitations

    Collected for specified, explicit and legitimate purposes.

  3. Data minimisation

    Adequate, relevant and limited to what is necessary.

  4. Accuracy

    Accurate and, where necessary, kept up-to-date.

  5. Storage limitations

    Retained only for as long as necessary.

  6. Integrity and confidentiality

    Processed in an appropriate manner to maintain security.

Edit this page

Know of a set of design principles that should be here? Contribute an example