The Seven Data Protection Principles
The data protection principles in Article 5 are the part of the GDPR you read once and rarely revisit, which is the wrong instinct. Every other obligation in the regulation is one of these principles applied to a situation. A lawful-basis question, a retention question, a breach question: each is a principle wearing the costume of a specific rule.
That is why Domain III of the CIPP/E Body of Knowledge, the syllabus the exam is built from, sets the principles near the front. Learn to name the principle a scenario offends and the paper stops reading as separate topics. Miss it and you argue the wrong point under time pressure.
Article 5 is the regulation in miniature
Article 5 holds seven principles. The first six sit in Article 5(1) and govern the processing itself. The seventh, accountability, sits in Article 5(2) and requires the controller to demonstrate compliance with the other six, not merely assert it. Read together they are a compressed version of the whole regulation, which is why an examiner can build almost any scenario from them. They are written as standards rather than bright-line rules, so the exam tests judgement over recall: you apply a principle to facts, you do not quote it. The data protection principles predate the GDPR; Convention 108 carried versions of them decades earlier.
The data protection principles that govern what you collect
Three principles do their work at the moment you decide to gather data at all.
Lawfulness, fairness and transparency
Lawfulness means processing rests on one of the six lawful bases in Article 6; without one, nothing else you do is compliant. Fairness asks whether the processing would disadvantage the person in a way they could not reasonably expect. Transparency requires you to tell them what you are doing in language they can follow, the duty behind every privacy notice and the reason transparency obligations carry their own articles. The exam trap is treating these three as one; a notice can be transparent and the processing still unfair.
Purpose limitation and data minimisation
Purpose limitation fixes why you hold the data. You name a specific purpose at collection and you do not later repurpose the data for something incompatible without a fresh basis. When a new use is proposed, the compatibility test weighs the link between the old and new purposes, the context of collection, the nature of the data and the impact on the person. Consent or a legal obligation can support a genuinely new purpose; a hopeful business case cannot. Data minimisation fixes how much you hold: only what the purpose needs, no convenient extra. The two interlock, and this is where proportionality lives. Candidates lose marks by reading these as vague good manners; they are testable limits, and a scenario that collects data in case it proves useful later has already failed both.
The data protection principles that govern what you keep
Once data is in your systems, three more principles govern its life there. Accuracy requires you to keep data correct and up to date, and to rectify or erase what is wrong; a stale record is not a harmless one. Storage limitation requires you to keep data no longer than the purpose needs, then delete it. An indefinite backup is therefore a compliance problem, not a safety net, and that tension is the heart of the backup paradox. Integrity and confidentiality is the security principle: appropriate technical and organisational measures against loss, damage and unauthorised access. It does not name specific controls; it requires measures appropriate to the risk, which is why a sole trader and a hospital owe different things under the same words.
Accountability, and how the exam hides a principle in a scenario
Accountability is the principle that turns the other six from aspiration into obligation. It is not enough to comply; you must hold the records, assessments and policies that show you comply. In practice this is the record of processing activities, the impact assessments and the policies a supervisory authority can ask to see on demand. The thread runs into the accountability duties of Domain IV, and it is why documentation is never optional.
The exam rarely says which principle applies. It gives you a company retaining CV data for eight years, or reusing support-line recordings to train a model, and asks what is wrong. The skill is to strip the scenario to its load-bearing fact and match it to a principle: the CVs are storage limitation, the recordings are purpose limitation. Name the principle first and the correct answer usually follows without a fight.
Get the seven straight and the rest of the CIPP/E syllabus reads as their application rather than a fresh pile of rules. If you want a structured way to drill them, the study resources at 22Academy are the place to start.