GDPR in practice: the 7 principles and 6 lawful bases
The General Data Protection Regulation (Regulation (EU) 2016/679) has a fearsome reputation and a surprisingly small core. Strip away the recitals and the case law and you are left with two things you actually have to internalise: the seven principles in Article 5, which describe how personal data must be handled, and the six lawful bases in Article 6, one of which you need before you process anything at all. Get those right and the rest of GDPR is mostly detail.
It has been in force since 25 May 2018, it applies to controllers and processors alike, and it reaches any organisation offering goods or services to, or monitoring, people in the EU, wherever that organisation sits. So this is not only a European company's problem. If you have EU users, it is your problem too.
The seven principles (Article 5)
Article 5 is the spine of the whole regulation. Every other obligation is really one of these principles made specific:
- Lawfulness, fairness and transparency: process data on a valid legal basis, do not do anything sneaky with it, and tell people what you are doing.
- Purpose limitation: collect data for specified, explicit purposes, and do not quietly repurpose it later.
- Data minimisation: collect only what you actually need for that purpose, not everything you might one day want.
- Accuracy: keep it correct and up to date, and correct or erase what is wrong.
- Storage limitation: keep it only as long as you need it, then delete it.
- Integrity and confidentiality: protect it with appropriate security (this is the tie back to Article 32).
- Accountability: be able to demonstrate all of the above. This is the principle that turns good intentions into documented evidence.
Accountability is the principle everyone forgets and every regulator asks about first. It is not enough to be compliant. You have to be able to prove it, on demand, with records.
The six lawful bases (Article 6)
You cannot process personal data on vibes. Article 6 gives you six lawful bases, and you must pick the right one for each processing activity before you start:
- Consent: freely given, specific, informed and unambiguous, and as easy to withdraw as it was to give.
- Contract: processing necessary to perform a contract with the individual, or to take steps at their request before entering one.
- Legal obligation: processing you must do to comply with the law.
- Vital interests: processing to protect someone's life.
- Public task: processing to carry out a task in the public interest or under official authority.
- Legitimate interests: processing necessary for your (or a third party's) legitimate interests, unless the individual's rights override them. This one needs a documented balancing test.
The question that decides your basis
The mistake teams make is defaulting to consent for everything. Consent is fragile: it can be withdrawn, and then your lawful basis vanishes. For a lot of ordinary business processing, contract or legitimate interests is the sturdier and more honest choice. The question to ask for each activity is simple: why am I really doing this, and is consent the true reason or just the reflex? Answer that and the basis usually picks itself.
In Compliance One, every processing activity in your Record of Processing carries its lawful basis, your legitimate-interests balancing tests are stored alongside the activities they justify, and consent is tracked where you rely on it. The seven principles map straight onto your ISO 27701 and ISO 27001 controls, so the accountability principle stops being a scramble and becomes evidence you can hand an auditor or a supervisory authority without a fire drill.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.