
You wouldn’t jump into a swimming pool without checking the rules first. The same should apply before your business starts collecting or using personal data.
The UK GDPR can sometimes feel like a long list of complicated requirements. But underneath all the detail are seven fundamental principles. These principles sit at the heart of the UK GDPR and should guide the way your business handles personal information. Here’s what they mean in practice.
1. Lawfulness, fairness and transparency
First, you need to have a valid reason for using someone’s personal data.
This is where lawful basis comes in. Depending on what you’re doing, this could include consent, contract, legal obligation or legitimate interests. But having a lawful basis isn’t the whole story. Your use of the information must also be fair, and people should understand what you’re doing with their data.
Ask yourself:
Do we have a lawful basis, and would the person reasonably expect us to use their information this way?
Your privacy information should explain what you’re doing in clear, understandable language.
2. Purpose limitation
Personal data shouldn’t be collected simply because it might be useful one day. You should have a clear purpose for collecting it and generally use it for that purpose.
For example, a customer gives you their email address so you can manage their order. That doesn’t automatically mean you can use the same address for every marketing activity you can think of.
Before using existing information for something new, stop and ask whether the new use is compatible with the original purpose and whether you have the necessary legal basis.
A good question to ask:
Why did we collect this information in the first place – and does that still explain why we’re using it now?
The ICO’s current guidance notes that the rules around compatibility and re-use have been updated following the Data (Use and Access) Act.
3. Data minimisation
More data isn’t necessarily better data.
The principle of data minimisation means you should only collect personal information that is adequate, relevant and necessary for what you’re trying to achieve.
For example, if you’re organising a delivery, you may need someone’s name and address. You probably don’t need to know their favourite film. This is a particularly useful principle when designing:
- Customer forms
- Employee records
- Website forms
- Surveys
- Marketing databases
- AI prompts and systems
Ask yourself:
Do we genuinely need every piece of information we’re asking for?
If the answer is no, don’t collect it.
4. Accuracy
Your business decisions can only be as good as the information behind them.
The accuracy principle means personal data should be accurate and, where necessary, kept up to date. If you discover that information is wrong, you should take reasonable steps to correct it.
Think about something as simple as an old customer address.
If your business continues using an outdated address, it could lead to incorrect correspondence, failed deliveries or other problems.
Ask yourself:
How do we know the information we’re relying on is still accurate?
You don’t necessarily need to constantly check every piece of information. But you should have sensible processes for correcting information when errors are identified.
5. Storage limitation
Just because you can keep personal data doesn’t mean you should. The storage limitation principle says personal data should not be kept in an identifiable form for longer than necessary for the purpose for which it was collected, subject to certain exceptions.
This is why businesses need sensible retention periods. Think about all the places old information can hide:
- Former employees’ records
- Old customer accounts
- Outdated marketing lists
- Archived emails
- Shared drives
- Spreadsheets
- Paper files
- Cloud storage
A useful exercise is to ask:
What personal data are we keeping, why are we keeping it, and when should it be deleted?
If nobody can answer those questions, it’s probably time for a review.
6. Integrity and confidentiality – security
Personal data needs appropriate protection against unauthorised or unlawful access, as well as accidental loss, destruction or damage. In plain English: keep people’s information safe. That could involve technical measures such as passwords, access controls, encryption and backups, alongside organisational measures such as staff training, policies and procedures.
Security isn’t just an IT issue. A member of staff sending a spreadsheet containing customer information to the wrong person can be just as much a data protection problem as a cyberattack.
Ask yourself:
Who has access to our personal data, and do they actually need it?
Access should be appropriate to the role and the risks involved.
7. Accountability
This is the principle that ties the others together. Accountability means your business is responsible for complying with the data protection principles and must be able to demonstrate that it is doing so.
It’s not enough to say:
“We’re GDPR compliant.”
You should be able to show what you’ve done. That could include things such as:
- Data protection policies
- Privacy notices
- Records of processing
- Staff training
- Retention policies
- Data protection impact assessments where required
- Contracts with suppliers and processors
- Records of data breaches
- Evidence of regular reviews
Good data protection is about having the right processes in place – and being able to demonstrate them when needed.
So, are you following the rules?
The seven principles aren’t seven separate jobs to complete and forget about. They should influence the whole data lifecycle, from the moment you collect personal information to the moment you securely delete it.
A simple way to remember them is:
- Be fair.
- Know why you’re collecting it.
- Don’t collect more than you need.
- Keep it accurate.
- Don’t keep it forever.
- Keep it secure.
- And be able to prove you’re doing all of the above.
The ICO describes these principles as being at the heart of the UK GDPR, so they’re a good place to start if you’re reviewing your business’s data protection arrangements.
Test the GDPR waters
Take 10 minutes and think about the different types of personal data your business holds – your customer database, your employees, your suppliers.
Ask:
- Why do we have it?
- What’s our lawful basis for using it?
- Are we collecting anything we don’t actually need?
- Is it accurate?
- How long are we keeping it?
- Who can access it?
- Can we demonstrate that we have the right processes in place?
If you can’t answer some of these questions, don’t panic. It simply shows you where to start.
Data protection doesn’t have to be complicated. The key is understanding what data you have, why you’re using it and what you’re doing to protect it.
