GDPR
Chapter II - Principles

GDPR GDPR-Art.5: Principles relating to processing of personal data

Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 234 controls across 76 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ACC-1 ACC-1 Do not use biometric or photo-taking time clocks to control working hours
  • ACC-2 ACC-2 Do not reuse access-control logs for another purpose such as checking hours
  • ACC-3 ACC-3 Do not track movements inside the premises or check staff representatives' movements and delegation hours
  • ACC-5 ACC-5 Keep identification data for the authorisation period, access logs three months and time-tracking data up to five years
  • ACT-1 ACT-1 Define the objective and scope of each control device and identify the risks to employees' rights before installing it
  • ACT-2 ACT-2 Show the device is necessary: no less intrusive means, only the data, retention and access strictly required
  • ACT-3 ACT-3 Do not place staff under constant or permanent surveillance
  • ACT-4 ACT-4 Do not use a device for a hidden purpose other than the one declared
  • ACT-5 ACT-5 Keystroke loggers are disproportionate for monitoring staff
  • CALL-1 CALL-1 Listen to or record calls only occasionally, for training, evaluation, service quality or legally provided proof, collecting only what is needed
  • CALL-2 CALL-2 Do not record calls permanently or systematically unless a law requires it
  • CALL-5 CALL-5 Keep recordings up to six months and analysis documents up to one year
  • GEO-1 GEO-1 Use vehicle geolocation only for the purposes the CNIL recognises
  • GEO-2 GEO-2 Do not use geolocation to check speed, to monitor continuously, for free-roaming staff, staff representatives or outside working time
  • GEO-6 GEO-6 Keep location data two months, one year for route optimisation or proof, five years for working time
  • NET-2 NET-2 Do not receive automatic copies of all staff email, and keep connection logs no more than six months
  • PHN-1 PHN-1 Mask the last four digits on call records, keep telephony data a year at most and never monitor representatives' calls
  • SCR-1 SCR-1 Do not couple screen captures with call recording
  • SCR-2 SCR-2 Couple screen video with call recording only for training, with every listed safeguard
  • TLW-1 TLW-1 Do not monitor teleworkers constantly by webcam, audio, screen sharing, keyloggers or forced presence checks
  • VID-1 VID-1 Install cameras only for a defined, lawful and legitimate purpose
  • VID-2 VID-2 Point cameras at entrances, exits, emergency exits, circulation routes and storage areas, not at workstations
  • VID-3 VID-3 Do not film break or rest areas, toilets, or union and staff representative premises
  • VID-5 VID-5 Record sound only in particular situations, triggered by an employee
  • VID-7 VID-7 Set a retention period tied to the purpose, in principle not over one month, and log extractions

Canadian PIPEDA · 7 controls

APPI · 6 controls

  • APPI-A17 Specification of the Purpose of Use
  • APPI-A18 Restriction on Handling Beyond the Purpose of Use
  • APPI-A19 Prohibition of Improper Use
  • APPI-A20 Proper Acquisition and Special Care Required Personal Information
  • APPI-A22 Accuracy and Deletion of Personal Data
  • APPI-A23 Security Control Measures
  • 3(a) 3(a) Purposes specified in detail and documented in writing for every camera; 'safety' is not a purpose
  • 3.1.2(a) 3.1.2(a) Necessity: less intrusive alternatives first
  • 3.1.2(c) 3.1.2(c) Necessity in how evidence is kept: black box, real-time viewing or guards
  • 5(b) 5(b) Minimise the capture of other sensitive information, even outside Article 9
  • 5.1(d) 5.1(d) Biometrics: delete comparison templates immediately and keep enrolment templates only for the purpose
  • 8 8 Storage: a few days, deleted automatically; beyond 72 hours needs stronger justification
  • 3.1(a) 3.1(a) Specified, legitimate purposes and data that are adequate, relevant and not excessive
  • 3.1(b) 3.1(b) Proportionality and subsidiarity, whatever the legal ground, tested before monitoring starts
  • 3.1(d) 3.1(d) Accurate data kept no longer than needed, with a set retention period
  • 5.3(h) 5.3(h) Prefer prevention to detection: block rather than monitor
  • 5.7(c) 5.7(c) No location monitoring outside agreed working hours, save a proportionate theft safeguard
  • AUCDR-PS-11 Privacy Safeguard 11 - Quality of CDR data
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data
  • AUCDR-PS-4 Privacy Safeguard 4 - Dealing with unsolicited CDR data
  • AUCDR-PS-6 Privacy Safeguard 6 - Use or disclosure of CDR data
  • AUCDR-PS-9 Privacy Safeguard 9 - Adoption or disclosure of government related identifiers
  • CAYDPA-P1 First Principle - Fair and Lawful Processing
  • CAYDPA-P2 Second Principle - Purpose Limitation
  • CAYDPA-P3 Third Principle - Adequate, Relevant and Not Excessive
  • CAYDPA-P4 Fourth Principle - Accuracy
  • CAYDPA-P5 Fifth Principle - Storage Limitation
  • PIPL-Art19 Retention Period Limitation
  • PIPL-Art5 Lawfulness, Good Faith, Necessity
  • PIPL-Art6 Purpose Limitation and Minimisation
  • PIPL-Art8 Quality of Personal Information
  • PIPL-Art9 Security Responsibility of Handlers

ISO 27701:2019 · 5 controls

  • 7.2.1 Identify and document purpose
  • 7.4.2 Limit processing
  • 7.4.3 Accuracy and quality
  • 7.4.5 PII de-identification and deletion at the end of processing
  • 7.4.7 Retention

NIST SP 800-53 Rev 5 · 5 controls

  • NIST800-PM-22 PM-22 Personally Identifiable Information Quality Management
  • NIST800-PM-25 PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research
  • NIST800-PT-2 PT-2 Authority to Process Personally Identifiable Information
  • NIST800-PT-3 PT-3 Personally Identifiable Information Processing Purposes
  • NIST800-SI-12 SI-12 Information Management and Retention
  • MYHR-CUD-1 Authorised collection, use and disclosure only
  • MYHR-CUD-2 Prohibition on unauthorised collection, use and disclosure
  • MYHR-CUD-3 Use limited to My Health Record purposes
  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator
  • APP-10 APP 10 - Quality of personal information
  • APP-11 APP 11 - Security of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-6 APP 6 - Use or disclosure of personal information

CCPA/CPRA · 4 controls

  • CCR §7100-7102 Recordkeeping Requirements
  • 1798.100(c) Keep collection and use necessary and proportionate
  • §1798.100 General Duties of Businesses that Collect Personal Information
  • §1798.130(a)(5)(C) Notice at Collection
  • SD134-10 Retention Limitation
  • SD134-5 Purpose Limitation
  • SD134-6 Data Minimisation
  • SD134-7 Accuracy and Quality
  • RDCOC-ANO-01 Anonymisation Criteria
  • RDCOC-PSE-01 Pseudonymisation Standards
  • RDCOC-RET-01 Retention and Archival
  • RDCOC-SCO-01 Scope of Processing Activities
  • s25 s 25 Public bodies transfer data to other bodies only on the listed conditions and with purpose binding
  • s26-5 s 26(5) Take measures to ensure the GDPR principles are met in employee data processing
  • s4-3 s 4(3) Store and use video data only for the stated purpose, with narrow onward uses
  • s47 s 47 Apply the six principles to law enforcement processing

SOC 2 · 4 controls

  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P4.1 P4.1 Limiting use to identified purposes
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P7.1 P7.1 Quality of personal information
  • UZB-DPL-05 Purpose Limitation Principle
  • UZB-DPL-06 Data Minimisation
  • UZB-DPL-07 Data Accuracy and Quality
  • UZB-DPL-15 Retention and Destruction

Colorado Privacy Act · 3 controls

  • EST-IKS-§14-21 Principles of processing by law enforcement authorities
  • EST-IKS-§2 Specifications for application of the Act and Regulation (EU) 2016/679
  • EST-IKS-§6 Processing for scientific and historical research and official statistics
  • L1121-1 L1121-1 Justify and proportion every restriction on rights and freedoms
  • L1221-6 L1221-6 Ask candidates only for information with a direct and necessary link to the job
  • L1222-2 L1222-2 Ask employees only for information with a direct and necessary link to evaluating their aptitudes
  • 5.1 5.1 Lawful, fair and employment-related processing
  • 5.2 5.2 Use only for the original purpose
  • 8.4 8.4 Periodic accuracy checks

ISO 27001:2022 · 3 controls

  • 5.33 Protection of records
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 8.10 Information deletion

ISO 27002:2022 · 3 controls

  • 5.33 Protection of records
  • 5.34 Privacy and protection of PII
  • 8.10 Information deletion
  • Art. 113 Art. 113 Keep pre-employment and in-employment data collection to what is relevant (Statute art. 8, D.Lgs. 276/2003 art. 10)
  • Art. 123 Art. 123 Erase or anonymise traffic data when no longer needed, within the billing and consent limits
  • Art. 132 Art. 132 Retain traffic data for criminal justice only for the statutory periods and protect and destroy them
  • 42 s 42 No surveillance of a worker who is not in a workplace, with limited exceptions
  • 43 s 43 No use or disclosure of records from non-deactivatable tracking outside the workplace
  • CSL-Art40 Confidentiality of User Information - Art. 40
  • CSL-Art42 Personal Information Protection and Breach Handling - Art. 42
  • CDR-PS-1 Privacy Safeguard 1: Open and Transparent Management of CDR Data
  • CDR-PS-11 Privacy Safeguard 11: Quality of CDR Data

DORA · 2 controls

  • EMV3DS-16 App-based channel and device information
  • EMV3DS-21 Cardholder data protection and minimisation

EU AI Act · 2 controls

  • EUAI-Art.10 Data and data governance
  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
  • EGY-PDPL-Art.18 Obligations of the direct-marketing sender
  • EGY-PDPL-Art.3 Conditions for lawful collection and processing
  • UAE-PDPL-Art.1_2_3 Scope, definitions and applicability (UAE PDPL Articles 1-3)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • AL-DPA-2 Data Quality Principles

C5 (Germany) · 1 control

  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept

COPPA · 1 control

  • COPPA-312.10 Data Retention and Deletion (Written Retention Policy)
  • DEPA-4.2 Personal Information Protection
  • CDMC-KC10 Data Protection Impact Assessments
  • ESRB-PC-10 Data minimisation for child personal information

ETSI EN 303 645 · 1 control

  • EN303645-6 Data Protection Provisions for Consumer IoT (Clause 6)
  • PSD2-Art.94 Data protection (PSD2 Article 94) - GDPR alignment
  • PLD-Art.6 Categories of damage covered (PLD Article 6)
  • SEV-Art.22_23 Access to information + access to justice + confidentiality (Seveso III Articles 22 and 23)
  • FATF-R.10_11 Customer Due Diligence + Record Keeping (FATF R.10 and R.11)

FedRAMP High · 1 control

  • SI-12 Information Management and Retention

FedRAMP Moderate · 1 control

  • SI-12 Information Management and Retention
  • Art. 8 Art. 8 Do not investigate workers' opinions or facts irrelevant to their professional aptitude

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • s16 s 16 No surveillance with a work device while the employee is not at work
  • CIA-RET-07 Retention and destruction of credit information
  • 503.001(c)(3) 503.001(c)(3) Destroy within a reasonable time, at the latest one year after the purpose expires
  • ZDPA-14 Retention and Disposal

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter II - Principles

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 234 it maps to, and the evidence behind each claim, over MCP and REST.