The seven principles of UK GDPR
Sign in to track progress on this lesson.
01 — Main lesson
Full walk-through. · 7.3 MB
Spoken script — useful when names or terms sound ambiguous.
Welcome back to your data protection walking series. This is the next lesson, and today we are looking at the seven principles that sit at the heart of the United Kingdom General Data Protection Regulation.
You already know how the law splits data into standard personal data, special category data, and criminal offence data. Those three categories tell you what you are protecting. The seven principles tell you how you must protect it. Every organisation that handles information about you must follow these rules, and the higher the sensitivity, the more seriously each principle bites.
Before we walk through each one, picture them as seven questions you can ask whenever you hand over your details. Is this lawful and fair? Why do they really want it? Do they need all of it? Is it correct? How long will they keep it? Is it safe? And can they prove they thought this through? Those questions map directly onto the seven principles, and they become second nature once you know the labels.
The first principle is lawfulness, fairness, and transparency. Any processing must be lawful, which means the organisation needs a valid basis such as consent, contract, or legal obligation. But it also has to be fair. Fairness means no misleading small print, no pre-ticked boxes, and no using your data in ways that sneak outside your reasonable expectations. Transparency means a clear privacy notice you can actually understand, often layered so the key points are visible and the detail is available if you want it. Think about the gym from last time. Your name and email were covered by your membership contract. That is lawful and transparent. But when they asked for your health history or took a fingerprint scan, that special category data needed explicit consent and a separate clear notice. If they buried the health questionnaire in page twenty of a general form, or pre-ticked a box agreeing to share your medical details with a supplement company, they would break fairness and transparency in one move. Fairness also looks at power. If your employer demands consent as a condition of your job, that consent is rarely genuine because you fear losing your wages. In those cases, the employer must rely on a different lawful basis and still tell you exactly what is happening.
The second principle is purpose limitation. Data must be collected for specified, explicit, and legitimate purposes, and it cannot be used for anything incompatible with those original purposes. Once an organisation tells you why they want the data, that is the cage they have built. Imagine the council running that town hall meeting about the bypass road. They collected your name and address to prove who attended, and your political opinion to gauge sentiment. They cannot later use that opinion list to target you with campaign emails for a particular party. That is a new incompatible purpose. Picture a secondary school. You gave them your phone number so they could call you if your child had an accident. If the head teacher then sold that parent contact list to a school photograph company, that would violate purpose limitation. You consented to emergency contact, not advertising. Even a charity collecting donations for famine relief cannot use donor financial data later to push political campaigns without a fresh lawful basis. The principle matters even more when the data is sensitive. Using health data collected for occupational safety to later decide who gets a promotion is exactly the kind of drift that triggers regulatory action.
The third principle is data minimisation. The data collected must be adequate, relevant, and limited to what is necessary. Do not collect stuff you do not need. If you apply for an office job and the employer asks for your height, weight, and marital status, that is likely a minimisation failure because none of those facts are relevant. Now apply that to the three tiers you know. A retailer needs your postal address to post shoes. That is necessary. But if the same retailer asks for your ethnic origin to complete a simple purchase, that is not minimal, and because ethnicity is special category data, the failure is doubly serious. Or consider the security firm running fingerprint scans for clocking in. If the firm could achieve the same goal with a swipe card, collecting fingerprints breaches minimisation because the intrusion is greater than necessary. A doctor's surgery booking you a taxi does not need your religion or your political opinions. When you see a form with dozens of optional fields that seem irrelevant, that is often a sign that the organisation has not thought hard about minimisation.
The fourth principle is accuracy. Personal data must be accurate and, where necessary, kept up to date. Every organisation must take reasonable steps to ensure that inaccurate data is erased or rectified without delay. This is not just about spelling your name right. It is about facts that affect your life. Imagine the warehouse from last time. The occupational health nurse records that you have a back condition limiting heavy lifting. Six months later you recover fully and your doctor clears you. If the warehouse still keeps the old restriction on file and excludes you from promotion, they are breaching accuracy. You have a right to ask them to correct it. A retailer sending parcels to your old flat because they never updated your address is a basic accuracy failure. Or picture the youth football club. A volunteer has an old criminal records certificate showing an allegation that was fully disproved in court. If the club keeps that unproven allegation and blocks the volunteer from coaching, the inaccuracy causes real harm. For standard data, an out of date email is annoying. For criminal offence data, an inaccurate record can destroy a career.
The fifth principle is storage limitation. Data must be kept for no longer than is necessary. Organisations need retention schedules, and they cannot keep your information forever just because storage is cheap. Think about the security firm again. They run a disclosure and barring service check when you are hired. Once they have verified you are suitable, they do not need the detailed certificate for ten years. Sector guidance often says they should destroy it after six months or a year, keeping only a record that the check was completed. The school must not keep old vetting records for volunteers who left years ago. The gym should delete your health questionnaire once your membership ends and there is no ongoing litigation. Special category data and criminal offence data should have the shortest retention periods because the risk of harm grows with time. When you see an organisation keeping customer records dating back two decades, ask whether that is genuine need or simple hoarding. That old email marketing list from two thousand eight is not a business asset if those customers have not engaged for fifteen years. It is a liability. Hoarding violates storage limitation and increases the damage if a breach ever happens.
The sixth principle is integrity and confidentiality, often called the security principle. Personal data must be processed with appropriate security, including protection against unauthorised processing and against accidental loss, destruction, or damage. This is where technical measures meet the three data tiers. Standard personal data might sit behind strong passwords and network encryption. That is the baseline. Special category data, like the school nurse's health records or the gym's fingerprint templates, should have stronger safeguards, perhaps pseudonymisation where the identity is separated from the medical note, plus access limited to specific trained staff. Criminal offence data, like the safeguarding officer's vetting files, might be stored in a locked cabinet with a named key holder, or in an encrypted folder with audit logs showing exactly who opened it. Remember the sleep app from the last lesson. If it stores your therapy notes and anxiety levels as unencrypted text in a basic cloud folder while your email is at least encrypted, that is backwards security. The health journal should be the most protected thing in the system. The principle is not about absolute perfection. It is about appropriate security relative to the risk. Leaking an email list is bad. Leaking unencrypted health records because a laptop was left on a train is a disaster. Leaking criminal intelligence because there was no password on the shared drive is catastrophic. The Information Commissioner's Office has issued severe fines because organisations failed to apply stronger security to higher risk data.
The seventh and final principle is accountability. The data controller is responsible for complying with all of these principles, and they must be able to demonstrate their compliance. Accountability turns the other six principles from good intentions into provable reality. It means organisations must maintain records of processing activities, documenting what data they hold, why they hold it, how long they keep it, and who they share it with. It means they must appoint a data protection officer in certain cases, such as public authorities or organisations that carry out large scale processing of special category data. It means they must carry out data protection impact assessments before high risk processing, like rolling out a biometric scanner across every office or building a centralised health database. Imagine the warehouse again. They cannot simply tell the Information Commissioner's Office that they protect union membership records. They must show the written policy, the staff training logs, the access controls, and the specific legal reasoning. If the regulator visits, the organisation needs evidence, not just reassuring words. Accountability also means reporting breaches within seventy two hours. A school that loses a laptop containing unencrypted special category data cannot stay silent. The principle forces them to own the mistake, notify the regulator, and often notify you too, so you can take protective steps.
These seven principles are not abstract philosophy. They are the daily test that every organisation must pass. The next time you hand over your name and address for a delivery, remember lawfulness, fairness, and transparency, and ask whether the purpose is clear. When a form asks for extra details that seem irrelevant, think about data minimisation. When you hear about a company keeping records for decades, recall storage limitation. When you read about a hospital leak, remember that integrity and confidentiality demands stronger walls around the most sensitive files.
Because you already understand the three categories of data, you can now see how the principles layer on top. Standard personal data must be lawful, minimal, accurate, secure, and not kept forever. Special category data must meet all of those tests with extra rigour. Criminal offence data must be handled under an even sharper microscope, with specific legal authority and strict retention. Once you recognise the seven principles, privacy notices start to make real sense. You will spot when an organisation is vague about purpose, hoarding data, or silent on security. That is the skill that turns you from a passive data subject into an informed observer who asks the right questions.
Well done. You have now walked through the seven core principles of United Kingdom data protection law. Keep walking.
You already know how the law splits data into standard personal data, special category data, and criminal offence data. Those three categories tell you what you are protecting. The seven principles tell you how you must protect it. Every organisation that handles information about you must follow these rules, and the higher the sensitivity, the more seriously each principle bites.
Before we walk through each one, picture them as seven questions you can ask whenever you hand over your details. Is this lawful and fair? Why do they really want it? Do they need all of it? Is it correct? How long will they keep it? Is it safe? And can they prove they thought this through? Those questions map directly onto the seven principles, and they become second nature once you know the labels.
The first principle is lawfulness, fairness, and transparency. Any processing must be lawful, which means the organisation needs a valid basis such as consent, contract, or legal obligation. But it also has to be fair. Fairness means no misleading small print, no pre-ticked boxes, and no using your data in ways that sneak outside your reasonable expectations. Transparency means a clear privacy notice you can actually understand, often layered so the key points are visible and the detail is available if you want it. Think about the gym from last time. Your name and email were covered by your membership contract. That is lawful and transparent. But when they asked for your health history or took a fingerprint scan, that special category data needed explicit consent and a separate clear notice. If they buried the health questionnaire in page twenty of a general form, or pre-ticked a box agreeing to share your medical details with a supplement company, they would break fairness and transparency in one move. Fairness also looks at power. If your employer demands consent as a condition of your job, that consent is rarely genuine because you fear losing your wages. In those cases, the employer must rely on a different lawful basis and still tell you exactly what is happening.
The second principle is purpose limitation. Data must be collected for specified, explicit, and legitimate purposes, and it cannot be used for anything incompatible with those original purposes. Once an organisation tells you why they want the data, that is the cage they have built. Imagine the council running that town hall meeting about the bypass road. They collected your name and address to prove who attended, and your political opinion to gauge sentiment. They cannot later use that opinion list to target you with campaign emails for a particular party. That is a new incompatible purpose. Picture a secondary school. You gave them your phone number so they could call you if your child had an accident. If the head teacher then sold that parent contact list to a school photograph company, that would violate purpose limitation. You consented to emergency contact, not advertising. Even a charity collecting donations for famine relief cannot use donor financial data later to push political campaigns without a fresh lawful basis. The principle matters even more when the data is sensitive. Using health data collected for occupational safety to later decide who gets a promotion is exactly the kind of drift that triggers regulatory action.
The third principle is data minimisation. The data collected must be adequate, relevant, and limited to what is necessary. Do not collect stuff you do not need. If you apply for an office job and the employer asks for your height, weight, and marital status, that is likely a minimisation failure because none of those facts are relevant. Now apply that to the three tiers you know. A retailer needs your postal address to post shoes. That is necessary. But if the same retailer asks for your ethnic origin to complete a simple purchase, that is not minimal, and because ethnicity is special category data, the failure is doubly serious. Or consider the security firm running fingerprint scans for clocking in. If the firm could achieve the same goal with a swipe card, collecting fingerprints breaches minimisation because the intrusion is greater than necessary. A doctor's surgery booking you a taxi does not need your religion or your political opinions. When you see a form with dozens of optional fields that seem irrelevant, that is often a sign that the organisation has not thought hard about minimisation.
The fourth principle is accuracy. Personal data must be accurate and, where necessary, kept up to date. Every organisation must take reasonable steps to ensure that inaccurate data is erased or rectified without delay. This is not just about spelling your name right. It is about facts that affect your life. Imagine the warehouse from last time. The occupational health nurse records that you have a back condition limiting heavy lifting. Six months later you recover fully and your doctor clears you. If the warehouse still keeps the old restriction on file and excludes you from promotion, they are breaching accuracy. You have a right to ask them to correct it. A retailer sending parcels to your old flat because they never updated your address is a basic accuracy failure. Or picture the youth football club. A volunteer has an old criminal records certificate showing an allegation that was fully disproved in court. If the club keeps that unproven allegation and blocks the volunteer from coaching, the inaccuracy causes real harm. For standard data, an out of date email is annoying. For criminal offence data, an inaccurate record can destroy a career.
The fifth principle is storage limitation. Data must be kept for no longer than is necessary. Organisations need retention schedules, and they cannot keep your information forever just because storage is cheap. Think about the security firm again. They run a disclosure and barring service check when you are hired. Once they have verified you are suitable, they do not need the detailed certificate for ten years. Sector guidance often says they should destroy it after six months or a year, keeping only a record that the check was completed. The school must not keep old vetting records for volunteers who left years ago. The gym should delete your health questionnaire once your membership ends and there is no ongoing litigation. Special category data and criminal offence data should have the shortest retention periods because the risk of harm grows with time. When you see an organisation keeping customer records dating back two decades, ask whether that is genuine need or simple hoarding. That old email marketing list from two thousand eight is not a business asset if those customers have not engaged for fifteen years. It is a liability. Hoarding violates storage limitation and increases the damage if a breach ever happens.
The sixth principle is integrity and confidentiality, often called the security principle. Personal data must be processed with appropriate security, including protection against unauthorised processing and against accidental loss, destruction, or damage. This is where technical measures meet the three data tiers. Standard personal data might sit behind strong passwords and network encryption. That is the baseline. Special category data, like the school nurse's health records or the gym's fingerprint templates, should have stronger safeguards, perhaps pseudonymisation where the identity is separated from the medical note, plus access limited to specific trained staff. Criminal offence data, like the safeguarding officer's vetting files, might be stored in a locked cabinet with a named key holder, or in an encrypted folder with audit logs showing exactly who opened it. Remember the sleep app from the last lesson. If it stores your therapy notes and anxiety levels as unencrypted text in a basic cloud folder while your email is at least encrypted, that is backwards security. The health journal should be the most protected thing in the system. The principle is not about absolute perfection. It is about appropriate security relative to the risk. Leaking an email list is bad. Leaking unencrypted health records because a laptop was left on a train is a disaster. Leaking criminal intelligence because there was no password on the shared drive is catastrophic. The Information Commissioner's Office has issued severe fines because organisations failed to apply stronger security to higher risk data.
The seventh and final principle is accountability. The data controller is responsible for complying with all of these principles, and they must be able to demonstrate their compliance. Accountability turns the other six principles from good intentions into provable reality. It means organisations must maintain records of processing activities, documenting what data they hold, why they hold it, how long they keep it, and who they share it with. It means they must appoint a data protection officer in certain cases, such as public authorities or organisations that carry out large scale processing of special category data. It means they must carry out data protection impact assessments before high risk processing, like rolling out a biometric scanner across every office or building a centralised health database. Imagine the warehouse again. They cannot simply tell the Information Commissioner's Office that they protect union membership records. They must show the written policy, the staff training logs, the access controls, and the specific legal reasoning. If the regulator visits, the organisation needs evidence, not just reassuring words. Accountability also means reporting breaches within seventy two hours. A school that loses a laptop containing unencrypted special category data cannot stay silent. The principle forces them to own the mistake, notify the regulator, and often notify you too, so you can take protective steps.
These seven principles are not abstract philosophy. They are the daily test that every organisation must pass. The next time you hand over your name and address for a delivery, remember lawfulness, fairness, and transparency, and ask whether the purpose is clear. When a form asks for extra details that seem irrelevant, think about data minimisation. When you hear about a company keeping records for decades, recall storage limitation. When you read about a hospital leak, remember that integrity and confidentiality demands stronger walls around the most sensitive files.
Because you already understand the three categories of data, you can now see how the principles layer on top. Standard personal data must be lawful, minimal, accurate, secure, and not kept forever. Special category data must meet all of those tests with extra rigour. Criminal offence data must be handled under an even sharper microscope, with specific legal authority and strict retention. Once you recognise the seven principles, privacy notices start to make real sense. You will spot when an organisation is vague about purpose, hoarding data, or silent on security. That is the skill that turns you from a passive data subject into an informed observer who asks the right questions.
Well done. You have now walked through the seven core principles of United Kingdom data protection law. Keep walking.
02 — Refresh
Short recap. · 1.1 MB
Spoken script — useful when names or terms sound ambiguous.
Let us recap what you just learned. The United Kingdom General Data Protection Regulation is built on seven principles that guide every decision about personal data.
Lawfulness, fairness, and transparency means organisations need a valid legal basis, must not deceive you, and must tell you clearly what is happening. Purpose limitation means they cannot grab data for one reason and then use it for something entirely different. Data minimisation means they should only collect what they actually need for that specific job. Accuracy means keeping records correct and up to date, so old facts do not wrongly affect your life. Storage limitation means deleting data when it is no longer necessary, not keeping it forever just in case. Integrity and confidentiality means applying appropriate security, with stronger locks for more sensitive tiers like health records or biometric scans. Accountability means the organisation must prove compliance through records, policies, and sometimes a data protection officer.
Remember the warehouse, the school, and the gym. Your name and email had to be lawful and minimal. Your health records and fingerprints demanded extra fairness, tighter purpose, and stronger security. Vetting certificates had to be accurate, securely stored, and destroyed on schedule. The seven principles do not just apply to special category data or criminal offence data. They apply to everything, but they bite hardest where the risk is highest. When you fill out your next form or read your next privacy notice, run through the seven principles quickly. Ask why they want it, whether they need all of it, how long they will keep it, and how well they are protecting it. That mental checklist is your data protection compass. Keep that with you on your next walk. Well done.
Lawfulness, fairness, and transparency means organisations need a valid legal basis, must not deceive you, and must tell you clearly what is happening. Purpose limitation means they cannot grab data for one reason and then use it for something entirely different. Data minimisation means they should only collect what they actually need for that specific job. Accuracy means keeping records correct and up to date, so old facts do not wrongly affect your life. Storage limitation means deleting data when it is no longer necessary, not keeping it forever just in case. Integrity and confidentiality means applying appropriate security, with stronger locks for more sensitive tiers like health records or biometric scans. Accountability means the organisation must prove compliance through records, policies, and sometimes a data protection officer.
Remember the warehouse, the school, and the gym. Your name and email had to be lawful and minimal. Your health records and fingerprints demanded extra fairness, tighter purpose, and stronger security. Vetting certificates had to be accurate, securely stored, and destroyed on schedule. The seven principles do not just apply to special category data or criminal offence data. They apply to everything, but they bite hardest where the risk is highest. When you fill out your next form or read your next privacy notice, run through the seven principles quickly. Ask why they want it, whether they need all of it, how long they will keep it, and how well they are protecting it. That mental checklist is your data protection compass. Keep that with you on your next walk. Well done.