Accountability - the principle that underpins GDPR
Sign in to track progress on this lesson.
01 — Main lesson
Full walk-through. · 8.8 MB
Spoken script — useful when names or terms sound ambiguous.
Welcome back to your data protection walking series. This is the next lesson, and today we are going deep on the principle that holds the entire United Kingdom General Data Protection Regulation together.
You already know the seven principles from your last walk. You can probably hear them in your head. Lawfulness, fairness, transparency. Purpose limitation. Data minimisation. Accuracy. Storage limitation. Integrity and confidentiality. Today we are looking at the one principle that makes all the others real. Accountability.
Think of accountability as the spine of the law. Without it, the other six principles are just good advice. Nice ideas that organisations can ignore. Accountability says no. It flips the burden. The organisation must prove it is doing the right thing. It is not your job as a data subject to catch them out. It is their job to show they have thought, planned, documented, and acted.
So what does that actually look like on the ground? Imagine the regulator walks into that warehouse we talked about before. The one that processes union membership records and occupational health notes. Under accountability, the manager cannot just smile and say trust us, we are careful. They must pull out a file and show exactly what data they hold, why they hold it, how long they keep it, who can access it, and what legal basis they rely on. That file is called the record of processing activities. For most organisations, this is not a casual spreadsheet. It is a living document that lists every activity involving personal data. If the warehouse processes standard personal data like names and shift patterns, the record notes the lawful basis, probably contract or legitimate interests. But when it processes special category data like back injury records from the occupational health nurse, the record must go further. It must name the specific condition under the regulation that allows health data processing. It must note the extra safeguards. It must name the retention period and the destruction method. If the warehouse cannot produce that record, they have already failed accountability before the regulator even checks whether the data is accurate or secure.
These records are not optional for large organisations or those handling sensitive data on a wide scale. They must include the name and contact details of the organisation, the purposes of processing, a description of the categories of data subjects and the data itself, the recipients who receive it, any international transfers, and the envisaged time limits for erasure. If the warehouse processes criminal conviction data for its security guards, that must be listed separately with the specific legal authority.
Now scale that up. A large security firm running fingerprint scanners across six sites processes special category biometric data on a large scale. Because of that, accountability demands they appoint a data protection officer. This is not just an employee who likes privacy. It is a specific statutory role. The data protection officer must report to the highest level of management. They must have independent authority. They cannot be told to bury a problem because it upsets a contract. Their job is to monitor compliance, train staff, advise on data protection impact assessments, and act as the contact point for both the regulator and for you as a data subject. If the security firm tries to make the data protection officer also the head of security operations, with pressure to approve whatever the bosses want, that compromises independence and breaches accountability. The firm must also publish the data protection officer's contact details and make them easy to find.
You can contact the data protection officer directly if you feel your rights are being ignored. They must respond without undue delay and without charging you simply for asking. If the officer is hidden behind a general enquiries line and never gets back to you, that is another sign that accountability is cosmetic.
Speaking of data protection impact assessments, this is where accountability meets planning. Before an organisation does anything that is likely to result in high risk to individuals, they must conduct this assessment. It is not a quick email saying we think it is fine. It is a systematic review. Let us take the gym from earlier. Suppose the gym decides to replace membership cards with a facial recognition entry system. That is special category biometric data, and it is new technology with clear risks. Before they install a single camera, accountability says they must describe the processing in detail. They must assess necessity and proportionality. They must identify the risks to members, such as misidentification, data leakage, or loss of control over sensitive personal information. Then they must find concrete measures to reduce those risks. Maybe they realise a swipe card works just as well, so the facial recognition is neither necessary nor proportionate. Or maybe they go ahead but only after adding strict access controls, local storage instead of cloud, encryption of biometric templates, and a clear deletion policy when members leave. The data protection impact assessment must be written down. It must be reviewed and updated if circumstances change. If the gym skips this and just installs the cameras because they look modern, they have broken accountability. The regulator can then stop the processing or issue a fine. The assessment is not a one off box ticking exercise. It is a living part of the accountability proof.
Accountability also means building data protection into the design of any new project. Privacy by design and privacy by default are not separate laws. They are part of the accountability principle. Picture a council that wants a new online system for residents to report potholes. A team that ignores accountability will collect the resident's name, email, exact geolocation, and maybe a photo that accidentally captures a neighbour's number plate. They will store it all in a basic database with open access across departments. A team that takes accountability seriously will ask what they truly need. They will default to collecting only the road name and a contact email, not a permanent location log. They will build in automatic deletion once the repair is confirmed. They will train staff before the system goes live. They will run the data protection impact assessment before a single line of code is written. That is privacy by default. The assessment would catch the risks of the first approach. But accountability means the culture exists before the assessment is even drafted.
This proactive approach saves money and reputational damage. Retrofitting privacy after a system is built is expensive. Fixing a leaking database is harder than designing one that only collects what is needed in the first place.
Let us talk about third parties. Accountability does not end at your own front door. If the school from our earlier examples contracts a photograph company to take class pictures, and the company needs names and faces to match prints to pupils, the school remains accountable. They cannot shrug and say the photographer lost the data. They must have a written contract in place that binds the photographer to the same data protection standards. The contract must specify exactly what the photographer can do with the data, how long they keep it, and how they secure it. The school must carry out due diligence. Did they check the photographer's security practices? Have they ever had a breach? If the retailer from earlier uses a cloud software firm to store customer addresses, the retailer must also check that the cloud provider stores data in a country with adequate protection. Accountability means maintaining that paper trail. When the regulator asks, the retailer must show the contract, the risk assessment, the audit trail, and the evidence that they checked compliance regularly.
Then there is the moment everyone hopes never happens. A breach. Remember that seventy two hour deadline. A school discovers on a Monday morning that a laptop containing unencrypted special category health records has been left on a train. Accountability means someone must immediately assess the risk to the pupils involved. Will the loss likely result in harm to their physical or mental health, or damage to their rights and freedoms? If yes, the school must notify the Information Commissioner's Office within seventy two hours. Not when they feel like it. Not after they have had a few meetings and hoped the laptop turns up. Seventy two hours. The seventy two hour clock runs from the moment the organisation becomes aware of the breach, not from the moment they finish investigating it. So they must move quickly even while details are still unclear. They must also likely tell the parents directly so families can take protective steps, like watching for suspicious contact or fraud. If the school delays because the head teacher is on holiday and nobody else knows the protocol, that is a failure of accountability. The organisation must have clear internal policies naming who makes the decision, who contacts the regulator, and how the notification is documented. Accountability turns a panic into a protocol.
Now consider a different breach. The gym realises that a former employee still has remote access to the membership database, including those health questionnaires. The employee downloads a list and sells it to a supplement marketing firm. The gym discovers this on a Wednesday afternoon. Clock starts. They must investigate, contain the leak, and report. Accountability demands they also review how the former employee kept access. Was there no offboarding checklist? Was there no quarterly access audit? Accountability is not just about owning the mistake. It is about proving you have fixed the systemic gap. The records of that audit, the revised policy, the retraining log, all become evidence of compliance. If the gym simply fires the employee but does not fix the access controls, they have not met accountability. The principle demands ongoing proof of improvement.
You might wonder what all this means for you as an individual walking around your neighbourhood. It means you can ask. If you hand your data to a charity, a club, or an employer, you can ask them to show you their records of processing. You can ask whether they have a data protection officer. You can ask if they have carried out a data protection impact assessment for that new fingerprint scanner they just installed. Most small organisations will not hand you the full file on the spot, but the fact that you ask changes the dynamic. It reminds them that accountability is not an internal secret. It is a public promise. It is a legal requirement that they must be ready to demonstrate to you, to the regulator, and to the world.
You can also spot the absence of accountability. If an organisation cannot tell you why they need your data, that suggests no record of processing exists. If they have no idea who their data protection officer is, that suggests no one is monitoring compliance. If they look confused when you ask how long they keep your records, that points to no retention schedule. If they roll out a new app or a new camera system with no warning and no privacy notice update, that suggests no data protection impact assessment happened. These are red flags. They tell you that accountability is weak, which means all the other principles are probably weak too. A gym that cannot explain its retention policy probably keeps your health data forever. A school that cannot name its data protection officer probably has not trained its staff on handling sensitive records. A retailer with no processor contracts is playing roulette with your address and payment details.
Let us return to that warehouse one last time. The manager wants to prove accountability. They open a cabinet. Inside is the record of processing activities. It lists the standard personal data, the special category data, and the criminal offence data from vetting checks. It shows the legal basis for each. It references the data protection impact assessment carried out before the biometric clocking system was installed. It includes the signed contract with the occupational health provider. There is the staff training log showing that every supervisor attended data protection training last month. There is the data protection officer's contact card, independent and reporting directly to the board. There is the breach protocol, tested in a drill six months ago, with the phone number for the Information Commissioner's Office pinned beside it. That is what accountability looks like in practice. It is not exciting. It is careful, documented, repeatable, and provable.
The beauty of accountability is that it protects you even when you are not watching. Because the organisation knows it must be able to prove its compliance, it is motivated to get the other six principles right from the start. It collects less data because it knows it must justify every field in the record. It keeps data accurate because it knows inaccurate records undermine its file. It deletes old data because the record has a column for retention and destruction dates. It secures sensitive data because the record requires a description of safeguards. Accountability is the engine room. It quietly powers everything else.
So as you finish this walk, remember that accountability is the difference between an organisation that talks about privacy and one that can prove it. The next time you see a privacy notice, look past the polite words. Ask yourself whether that organisation has the records, the officer, the assessments, and the plans to back them up. That is the principle that underpins everything else. Keep walking.
You already know the seven principles from your last walk. You can probably hear them in your head. Lawfulness, fairness, transparency. Purpose limitation. Data minimisation. Accuracy. Storage limitation. Integrity and confidentiality. Today we are looking at the one principle that makes all the others real. Accountability.
Think of accountability as the spine of the law. Without it, the other six principles are just good advice. Nice ideas that organisations can ignore. Accountability says no. It flips the burden. The organisation must prove it is doing the right thing. It is not your job as a data subject to catch them out. It is their job to show they have thought, planned, documented, and acted.
So what does that actually look like on the ground? Imagine the regulator walks into that warehouse we talked about before. The one that processes union membership records and occupational health notes. Under accountability, the manager cannot just smile and say trust us, we are careful. They must pull out a file and show exactly what data they hold, why they hold it, how long they keep it, who can access it, and what legal basis they rely on. That file is called the record of processing activities. For most organisations, this is not a casual spreadsheet. It is a living document that lists every activity involving personal data. If the warehouse processes standard personal data like names and shift patterns, the record notes the lawful basis, probably contract or legitimate interests. But when it processes special category data like back injury records from the occupational health nurse, the record must go further. It must name the specific condition under the regulation that allows health data processing. It must note the extra safeguards. It must name the retention period and the destruction method. If the warehouse cannot produce that record, they have already failed accountability before the regulator even checks whether the data is accurate or secure.
These records are not optional for large organisations or those handling sensitive data on a wide scale. They must include the name and contact details of the organisation, the purposes of processing, a description of the categories of data subjects and the data itself, the recipients who receive it, any international transfers, and the envisaged time limits for erasure. If the warehouse processes criminal conviction data for its security guards, that must be listed separately with the specific legal authority.
Now scale that up. A large security firm running fingerprint scanners across six sites processes special category biometric data on a large scale. Because of that, accountability demands they appoint a data protection officer. This is not just an employee who likes privacy. It is a specific statutory role. The data protection officer must report to the highest level of management. They must have independent authority. They cannot be told to bury a problem because it upsets a contract. Their job is to monitor compliance, train staff, advise on data protection impact assessments, and act as the contact point for both the regulator and for you as a data subject. If the security firm tries to make the data protection officer also the head of security operations, with pressure to approve whatever the bosses want, that compromises independence and breaches accountability. The firm must also publish the data protection officer's contact details and make them easy to find.
You can contact the data protection officer directly if you feel your rights are being ignored. They must respond without undue delay and without charging you simply for asking. If the officer is hidden behind a general enquiries line and never gets back to you, that is another sign that accountability is cosmetic.
Speaking of data protection impact assessments, this is where accountability meets planning. Before an organisation does anything that is likely to result in high risk to individuals, they must conduct this assessment. It is not a quick email saying we think it is fine. It is a systematic review. Let us take the gym from earlier. Suppose the gym decides to replace membership cards with a facial recognition entry system. That is special category biometric data, and it is new technology with clear risks. Before they install a single camera, accountability says they must describe the processing in detail. They must assess necessity and proportionality. They must identify the risks to members, such as misidentification, data leakage, or loss of control over sensitive personal information. Then they must find concrete measures to reduce those risks. Maybe they realise a swipe card works just as well, so the facial recognition is neither necessary nor proportionate. Or maybe they go ahead but only after adding strict access controls, local storage instead of cloud, encryption of biometric templates, and a clear deletion policy when members leave. The data protection impact assessment must be written down. It must be reviewed and updated if circumstances change. If the gym skips this and just installs the cameras because they look modern, they have broken accountability. The regulator can then stop the processing or issue a fine. The assessment is not a one off box ticking exercise. It is a living part of the accountability proof.
Accountability also means building data protection into the design of any new project. Privacy by design and privacy by default are not separate laws. They are part of the accountability principle. Picture a council that wants a new online system for residents to report potholes. A team that ignores accountability will collect the resident's name, email, exact geolocation, and maybe a photo that accidentally captures a neighbour's number plate. They will store it all in a basic database with open access across departments. A team that takes accountability seriously will ask what they truly need. They will default to collecting only the road name and a contact email, not a permanent location log. They will build in automatic deletion once the repair is confirmed. They will train staff before the system goes live. They will run the data protection impact assessment before a single line of code is written. That is privacy by default. The assessment would catch the risks of the first approach. But accountability means the culture exists before the assessment is even drafted.
This proactive approach saves money and reputational damage. Retrofitting privacy after a system is built is expensive. Fixing a leaking database is harder than designing one that only collects what is needed in the first place.
Let us talk about third parties. Accountability does not end at your own front door. If the school from our earlier examples contracts a photograph company to take class pictures, and the company needs names and faces to match prints to pupils, the school remains accountable. They cannot shrug and say the photographer lost the data. They must have a written contract in place that binds the photographer to the same data protection standards. The contract must specify exactly what the photographer can do with the data, how long they keep it, and how they secure it. The school must carry out due diligence. Did they check the photographer's security practices? Have they ever had a breach? If the retailer from earlier uses a cloud software firm to store customer addresses, the retailer must also check that the cloud provider stores data in a country with adequate protection. Accountability means maintaining that paper trail. When the regulator asks, the retailer must show the contract, the risk assessment, the audit trail, and the evidence that they checked compliance regularly.
Then there is the moment everyone hopes never happens. A breach. Remember that seventy two hour deadline. A school discovers on a Monday morning that a laptop containing unencrypted special category health records has been left on a train. Accountability means someone must immediately assess the risk to the pupils involved. Will the loss likely result in harm to their physical or mental health, or damage to their rights and freedoms? If yes, the school must notify the Information Commissioner's Office within seventy two hours. Not when they feel like it. Not after they have had a few meetings and hoped the laptop turns up. Seventy two hours. The seventy two hour clock runs from the moment the organisation becomes aware of the breach, not from the moment they finish investigating it. So they must move quickly even while details are still unclear. They must also likely tell the parents directly so families can take protective steps, like watching for suspicious contact or fraud. If the school delays because the head teacher is on holiday and nobody else knows the protocol, that is a failure of accountability. The organisation must have clear internal policies naming who makes the decision, who contacts the regulator, and how the notification is documented. Accountability turns a panic into a protocol.
Now consider a different breach. The gym realises that a former employee still has remote access to the membership database, including those health questionnaires. The employee downloads a list and sells it to a supplement marketing firm. The gym discovers this on a Wednesday afternoon. Clock starts. They must investigate, contain the leak, and report. Accountability demands they also review how the former employee kept access. Was there no offboarding checklist? Was there no quarterly access audit? Accountability is not just about owning the mistake. It is about proving you have fixed the systemic gap. The records of that audit, the revised policy, the retraining log, all become evidence of compliance. If the gym simply fires the employee but does not fix the access controls, they have not met accountability. The principle demands ongoing proof of improvement.
You might wonder what all this means for you as an individual walking around your neighbourhood. It means you can ask. If you hand your data to a charity, a club, or an employer, you can ask them to show you their records of processing. You can ask whether they have a data protection officer. You can ask if they have carried out a data protection impact assessment for that new fingerprint scanner they just installed. Most small organisations will not hand you the full file on the spot, but the fact that you ask changes the dynamic. It reminds them that accountability is not an internal secret. It is a public promise. It is a legal requirement that they must be ready to demonstrate to you, to the regulator, and to the world.
You can also spot the absence of accountability. If an organisation cannot tell you why they need your data, that suggests no record of processing exists. If they have no idea who their data protection officer is, that suggests no one is monitoring compliance. If they look confused when you ask how long they keep your records, that points to no retention schedule. If they roll out a new app or a new camera system with no warning and no privacy notice update, that suggests no data protection impact assessment happened. These are red flags. They tell you that accountability is weak, which means all the other principles are probably weak too. A gym that cannot explain its retention policy probably keeps your health data forever. A school that cannot name its data protection officer probably has not trained its staff on handling sensitive records. A retailer with no processor contracts is playing roulette with your address and payment details.
Let us return to that warehouse one last time. The manager wants to prove accountability. They open a cabinet. Inside is the record of processing activities. It lists the standard personal data, the special category data, and the criminal offence data from vetting checks. It shows the legal basis for each. It references the data protection impact assessment carried out before the biometric clocking system was installed. It includes the signed contract with the occupational health provider. There is the staff training log showing that every supervisor attended data protection training last month. There is the data protection officer's contact card, independent and reporting directly to the board. There is the breach protocol, tested in a drill six months ago, with the phone number for the Information Commissioner's Office pinned beside it. That is what accountability looks like in practice. It is not exciting. It is careful, documented, repeatable, and provable.
The beauty of accountability is that it protects you even when you are not watching. Because the organisation knows it must be able to prove its compliance, it is motivated to get the other six principles right from the start. It collects less data because it knows it must justify every field in the record. It keeps data accurate because it knows inaccurate records undermine its file. It deletes old data because the record has a column for retention and destruction dates. It secures sensitive data because the record requires a description of safeguards. Accountability is the engine room. It quietly powers everything else.
So as you finish this walk, remember that accountability is the difference between an organisation that talks about privacy and one that can prove it. The next time you see a privacy notice, look past the polite words. Ask yourself whether that organisation has the records, the officer, the assessments, and the plans to back them up. That is the principle that underpins everything else. Keep walking.
02 — Refresh
Short recap. · 1.2 MB
Spoken script — useful when names or terms sound ambiguous.
Let us recap what you just learned. Accountability is the principle that makes the entire United Kingdom General Data Protection Regulation enforceable. It shifts the burden of proof to the organisation. They must demonstrate compliance, not just claim it.
That demonstration happens through several concrete tools. Organisations must maintain records of processing activities, documenting what data they hold, why they hold it, and how long they keep it. In certain cases they must appoint an independent data protection officer who reports to top management. Before high risk processing, like biometric scanning or large health databases, they must carry out a written data protection impact assessment. They must build privacy into projects from the start, using privacy by design and default. When they use outside companies, they must have written contracts and do proper checks. If a breach happens, they must report it to the regulator within seventy two hours and often tell the people affected. They must also train their staff and keep those training logs up to date. This documentation forms the evidence trail that separates genuine compliance from empty promises.
Accountability means an organisation cannot simply say trust us. It must open the file and prove that every other principle is being followed. That proof must exist before the regulator ever asks. When you deal with any organisation that holds your data, you can look for the signs. Do they know their purpose and their retention periods? Can they name their data protection officer? Have they thought through the risks before rolling out new technology? Can they show you a written policy? Those answers reveal whether accountability is real or just words. That is your power as a data subject. Keep that with you on your next walk. Well done.
That demonstration happens through several concrete tools. Organisations must maintain records of processing activities, documenting what data they hold, why they hold it, and how long they keep it. In certain cases they must appoint an independent data protection officer who reports to top management. Before high risk processing, like biometric scanning or large health databases, they must carry out a written data protection impact assessment. They must build privacy into projects from the start, using privacy by design and default. When they use outside companies, they must have written contracts and do proper checks. If a breach happens, they must report it to the regulator within seventy two hours and often tell the people affected. They must also train their staff and keep those training logs up to date. This documentation forms the evidence trail that separates genuine compliance from empty promises.
Accountability means an organisation cannot simply say trust us. It must open the file and prove that every other principle is being followed. That proof must exist before the regulator ever asks. When you deal with any organisation that holds your data, you can look for the signs. Do they know their purpose and their retention periods? Can they name their data protection officer? Have they thought through the risks before rolling out new technology? Can they show you a written policy? Those answers reveal whether accountability is real or just words. That is your power as a data subject. Keep that with you on your next walk. Well done.