Learning 2 – Principles and lawful processing

1. Section 2: Principles and lawful processing

1.1. 2.1 The seven data protection principles

UK data protection learning

2.1 The seven data protection principles

The standards that apply throughout the personal-data lifecycle.

  1. Lawfulness, fairness and transparency
    Use data legally, avoid unjustified harm or surprise, and be open about what is happening.
  2. Purpose limitation
    Collect data for specified, explicit and legitimate purposes and avoid incompatible reuse.
  3. Data minimisation
    Use only data that is adequate, relevant and limited to what is necessary.
  4. Accuracy
    Take reasonable steps to keep data accurate and, where necessary, up to date.
  5. Storage limitation
    Do not retain identifiable personal data longer than necessary.
  6. Integrity and confidentiality
    Use appropriate technical and organisational security measures.
  7. Accountability
    Take responsibility and keep evidence that demonstrates compliance.

Applying the principles together

A single action may involve several principles. For example, collecting detailed medical histories for a simple event registration could be unfair, excessive, poorly secured and retained too long.

Knowledge checkpoint

Answer each question before opening the suggested answer.

1. A form asks for passport details when only an email address is required. Which principle is most obvious?

Suggested answer: Data minimisation.

2. A customer database contains outdated addresses and no correction process. Which principle is most obvious?

Suggested answer: Accuracy.

3. An organisation has good controls but cannot show any policies, records or decisions. Which principle is weak?

Suggested answer: Accountability.


Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.