Page Banner

What are the golden rules of GDPR?

Home » Blog » What are the golden rules of GDPR?

Most people have heard of GDPR. Fewer people could tell you what it actually requires them to do. Whether you run a small business in Farnborough, manage a marketing team, or simply want to understand your rights as a data subject, knowing what the golden rules of GDPR are is one of the most practically useful things you can learn about data protection law in the UK.

GDPR, the General Data Protection Regulation, came into force across the EU in May 2018. The UK retained its own version following Brexit, now referred to as UK GDPR, which sits alongside the Data Protection Act 2018 and continues to shape how organisations collect, store, and use personal data. Getting these rules wrong can result in significant fines, reputational damage, and a serious loss of trust from the people whose data you hold.


What Are the 7 Golden Rules of GDPR?

The seven golden rules of GDPR are not a separate document or official checklist. They refer to the seven core principles that the regulation sets out as the foundation of lawful data processing, found in Article 5 of the UK GDPR.

These principles are: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Each one carries genuine legal weight, and organisations are expected to demonstrate compliance with all seven, not just pay lip service to them.

Looking to ensure your data remains GDPR compliant? Take a look at our Database Information here

Funeral Directors Database


What Are the 7 Regulations of GDPR That Every Organisation Must Follow?

Understanding the seven regulations in practical terms is where many businesses struggle. Lawfulness, fairness, and transparency means you must have a valid legal basis for processing data and be open with people about how and why you are using their information. Purpose limitation means data collected for one reason cannot simply be repurposed for something entirely different without proper justification.

Data minimisation is arguably one of the most overlooked rules: you should only collect the data you genuinely need, nothing more. Accuracy requires organisations to keep personal data up to date and correct errors promptly. Storage limitation means you cannot hold onto personal data indefinitely; there must be a defined retention period that is proportionate to the purpose. Integrity and confidentiality covers security, ensuring data is protected against unauthorised access, loss, or destruction. Finally, accountability is the principle that ties everything together, placing the responsibility firmly on the data controller to prove compliance, not just claim it.

GDPR PrinciplePlain English Meaning
Lawfulness, Fairness and TransparencyYou need a legal basis to process data and must be open about it
Purpose LimitationData can only be used for the reason it was originally collected
Data MinimisationOnly collect what you actually need
AccuracyKeep data correct and up to date
Storage LimitationDo not keep data longer than necessary
Integrity and ConfidentialityProtect data from breaches and unauthorised access
AccountabilityBe able to demonstrate your compliance


What Are the 6 Key Principles of GDPR and How Do They Differ?

You will sometimes see GDPR described as having six key principles rather than seven. This is because the accountability principle is often treated as an overarching obligation that sits above the others, rather than one of the six data processing principles listed in Article 5(1). In practice, the distinction matters less than understanding what each principle demands of your organisation.

The six data processing principles, viewed on their own, cover the complete lifecycle of personal data from collection through to deletion. They were designed to be read together, not in isolation, because a failure in one area frequently creates problems in another. A business that collects more data than it needs, for example, will almost certainly struggle to keep it accurate and secure over time.


What Are the 7 Principles of Data Privacy as Per GDPR?

The seventh principle is accountability, which elevates the others from passive obligations to active The Information Commissioner’s Office (ICO), which is the UK’s independent regulator for data protection, publishes clear guidance on all seven principles. The ICO makes clear that these are not aspirational targets but legal requirements, and that organisations must be able to show they are meeting them. You can read the full guidance directly on the ICO’s official website at ico.org.uk.

Organisations that process large volumes of personal data, or that handle sensitive categories of information such as health records or financial details, face the highest scrutiny. For a business operating in a connected town like Farnborough, where technology firms, defence contractors, and service businesses all handle substantial amounts of customer and employee data, getting the principles right is not optional. Regulators do not distinguish between a global corporation and a regional SME when it comes to the fundamental obligations.

Common GDPR Compliance FailureWhich Principle It BreachesPotential Consequence
Retaining customer data indefinitelyStorage LimitationICO enforcement action
Using email addresses for unsolicited marketingPurpose LimitationFines and subject access complaints
Storing data on unsecured spreadsheetsIntegrity and ConfidentialityData breach notification obligation
No privacy notice on a websiteLawfulness and TransparencyRegulatory warning or fine
Collecting unnecessary personal details on formsData MinimisationNon-compliance finding on audit
Contact Our Team: 01276 69 11 99


Putting the Golden Rules of GDPR Into Practice for Your Business

Understanding what the golden rules of GDPR are is one thing; embedding them into daily business operations is where the real work begins. For many organisations, this starts with a data audit: mapping out exactly what personal data you hold, where it came from, how it is stored, who has access to it, and how long you intend to keep it. Without that clarity, compliance is largely guesswork.

Training is another area that is frequently underestimated. The accountability principle does not just require a policy document sitting in a shared drive. It requires evidence that staff understand their obligations, that processes exist to handle subject access requests correctly, and that someone within the organisation has taken clear responsibility for data protection. Appointing a Data Protection Officer (DPO) is mandatory for some organisations and advisable for many more.

Compliance with UK GDPR is not a one-off project but an ongoing commitment that needs to be reviewed as your organisation changes, as technology evolves, and as the ICO publishes updated guidance. The golden rules exist to protect real people, not to create administrative burden, and businesses that approach them with that mindset tend to find compliance considerably less daunting than those who treat it purely as a legal checkbox exercise.

  • The seven GDPR principles cover the full data lifecycle, from collection and purpose through to accurate storage, security, and eventual deletion, and all seven carry equal legal weight under UK GDPR.
  • The accountability principle is the one most often overlooked, yet it is the principle that requires you to actively demonstrate compliance rather than simply assert it.
  • Organisations of all sizes operating in the UK, including those in sectors like technology, healthcare, marketing, and professional services, are expected to apply these principles consistently and be prepared to evidence their approach if the ICO comes knocking.

What Are the Golden Rules of GDPR: Frequently Asked Questions

What are the golden rules of GDPR in simple terms?

The golden rules of GDPR are the seven core principles set out in Article 5 of the UK GDPR that govern how personal data must be collected, used, and protected. They cover everything from needing a lawful basis for processing to keeping data accurate and deleting it when it is no longer needed.

How many principles does GDPR have?

GDPR has seven principles in total, though some sources refer to six because accountability is sometimes treated separately as an overarching obligation. In practice, all seven are legally binding and must be followed by any organisation processing personal data.

Is UK GDPR the same as EU GDPR?

UK GDPR is largely based on the EU version but operates as its own distinct framework following Brexit, enforced by the ICO rather than EU data protection authorities. For a fuller overview of GDPR and its history, the Wikipedia page on GDPR provides a useful reference point.

What is the accountability principle under GDPR?

The accountability principle requires organisations to take responsibility for their data processing activities and to be able to demonstrate compliance when asked. This means maintaining records, implementing policies, and training staff rather than simply assuming you are compliant.

What is data minimisation in GDPR?

Data minimisation means collecting only the personal data that is strictly necessary for the stated purpose, nothing additional. Organisations should review their forms and data collection processes regularly to ensure they are not gathering information out of habit rather than genuine need.

What counts as personal data under UK GDPR?

Personal data is any information that can identify a living individual, either directly or in combination with other data. This includes names, email addresses, IP addresses, location data, and even certain combinations of seemingly innocuous information.

Who enforces GDPR in the UK?

The Information Commissioner’s Office (ICO) is the UK’s independent supervisory authority for data protection and enforces UK GDPR. The ICO has the power to issue fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for serious breaches.

What is the purpose limitation principle?

Purpose limitation means that data collected for one specific, declared reason cannot be used for a different purpose without a fresh legal basis and, in most cases, fresh consent. It prevents organisations from using customer data collected during a sale, for example, to build unrelated marketing profiles.

Do small businesses have to comply with GDPR?

Yes, UK GDPR applies to all organisations that process personal data regardless of their size, though some lighter obligations apply to organisations with fewer than 250 employees. The ICO’s guidance at gov.uk/data-protection includes specific resources for small businesses.

What is a lawful basis for processing under GDPR?

A lawful basis is one of six legal justifications that must apply before you can process personal data, including consent, legitimate interests, and contractual necessity. Without a documented lawful basis, any data processing you carry out is unlawful under UK GDPR.

How long can you keep personal data under GDPR?

The storage limitation principle means there is no single fixed retention period; instead, data should be kept only for as long as it is needed for its original purpose. Organisations are expected to set and document their own retention schedules and delete or anonymise data once those periods expire.

What is integrity and confidentiality in GDPR?

Integrity and confidentiality refers to the obligation to protect personal data against accidental loss, destruction, or unauthorised access using appropriate technical and organisational security measures. This covers everything from encryption and access controls to staff training and physical security.

What happens if you breach GDPR?

A breach can trigger an obligation to report to the ICO within 72 hours if it is likely to result in a risk to individuals’ rights and freedoms. Depending on the severity, the ICO can issue warnings, enforcement notices, or substantial fines.

What is a subject access request under GDPR?

A subject access request (SAR) is a right given to individuals under GDPR to obtain a copy of the personal data an organisation holds about them. Organisations must respond to a valid SAR within one calendar month and cannot charge a fee in most circumstances.

Further Reading About Marketing Databases