Learning 2 – Principles and lawful processing
Completion requirements
1. Section 2: Principles and lawful processing
1.1. 2.1 The seven data protection principles
2.1 The seven data protection principles
The standards that apply throughout the personal-data lifecycle.
- Lawfulness, fairness and transparency
Use data legally, avoid unjustified harm or surprise, and be open about what is happening. - Purpose limitation
Collect data for specified, explicit and legitimate purposes and avoid incompatible reuse. - Data minimisation
Use only data that is adequate, relevant and limited to what is necessary. - Accuracy
Take reasonable steps to keep data accurate and, where necessary, up to date. - Storage limitation
Do not retain identifiable personal data longer than necessary. - Integrity and confidentiality
Use appropriate technical and organisational security measures. - Accountability
Take responsibility and keep evidence that demonstrates compliance.
Applying the principles together
A single action may involve several principles. For example, collecting detailed medical histories for a simple event registration could be unfair, excessive, poorly secured and retained too long.
Knowledge checkpoint
Answer each question before opening the suggested answer.
1. A form asks for passport details when only an email address is required. Which principle is most obvious?
Suggested answer: Data minimisation.
2. A customer database contains outdated addresses and no correction process. Which principle is most obvious?
Suggested answer: Accuracy.
3. An organisation has good controls but cannot show any policies, records or decisions. Which principle is weak?
Suggested answer: Accountability.
Official reference points
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.