Skip to main content
Category: Privacy Governance & Design

Demonstrating Compliance With Principles

Also known as: Demonstrating GDPR Compliance, Demonstrating Compliance with Data Protection Principles
Simply put

This refers to an organisation's ability to show, through evidence, that it is following data protection rules rather than simply claiming to do so. In addition to internal documentation, controllers can rely on tools such as codes of conduct and certification mechanisms to help evidence that they are meeting data protection principles. The relevant tools available may change over time, so organisations should check current official guidance.

Formal definition

The obligation on a data controller to be able to evidence its adherence to the data protection principles, an aspect of the accountability principle under the GDPR. Beyond maintaining internal records and documentation, controllers may choose to use supplementary tools such as approved codes of conduct and certification mechanisms to help demonstrate compliance with data protection principles, as noted by the European Commission. These tools are voluntary and supportive rather than exhaustive means of demonstrating compliance, and their availability and scope depend on the relevant mechanisms recognised at a given time; practitioners should verify the current position against the applicable official text and regulator guidance. Note that codes of conduct and certifications are generally supplementary evidence and do not by themselves establish full compliance, which remains context- and risk-dependent.

Why it matters

The accountability principle under the GDPR shifts the burden onto controllers: it is no longer sufficient to assert that data protection rules are being followed, an organisation must be able to evidence that adherence. Demonstrating compliance with the data protection principles is therefore central to how regulators assess an organisation's posture, and a lack of supporting documentation can undermine an otherwise sound processing activity when scrutiny arises, whether during a regulator investigation, a data subject complaint, or an audit.

Because the ability to demonstrate compliance is evidential in nature, organisations that maintain contemporaneous records and other supporting materials are generally better positioned to respond to inquiries than those relying on after-the-fact reconstruction. The European Commission notes that controllers may choose supplementary tools such as approved codes of conduct and certification mechanisms to help demonstrate compliance with data protection principles. These tools are voluntary and supportive rather than exhaustive, and adherence to a code or certification does not by itself establish full compliance, which remains context- and risk-dependent.

The practical significance is that demonstrating compliance is an ongoing exercise rather than a one-time deliverable. The specific mechanisms recognised at a given time can change, and the availability and scope of codes of conduct and certification schemes depend on the mechanisms formally recognised under the applicable framework. Practitioners should verify the current position against the applicable official text and regulator guidance rather than assume a fixed set of tools remains available or sufficient.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those responsible for accountability need to ensure the organisation can produce evidence of adherence to the data protection principles, and should assess whether tools such as approved codes of conduct or certification mechanisms are appropriate and currently available to support that evidence.
Data Controllers
As the parties on whom the obligation to demonstrate compliance falls, controllers must be able to evidence their adherence to the data protection principles. They may choose to use supplementary tools, while recognising these do not by themselves establish full compliance.
Privacy Lawyers and Advisers
Practitioners advising on accountability should distinguish between internal documentation and voluntary supplementary tools, and should verify the current recognised mechanisms and their scope against the applicable official text and regulator guidance, as the position can change over time.
Senior Management and Governance Functions
Leadership responsible for overall governance benefits from understanding that demonstrating compliance is evidential and ongoing, and that reliance on codes of conduct or certifications is supportive rather than a guarantee of compliance, which remains context- and risk-dependent.

Inside Demonstrating Compliance With Principles

Accountability Principle
Under Article 5(2) GDPR, the controller is responsible for, and must be able to demonstrate compliance with, the data protection principles set out in Article 5(1). Accountability is not merely about being compliant, but about being able to evidence that compliance to supervisory authorities and data subjects.
Records of Processing Activities (ROPA)
Documentation maintained under Article 30 by controllers and processors, describing processing operations. This is a core evidentiary tool, though certain limited exemptions may apply for smaller organisations subject to conditions in the Article; practitioners should verify the current threshold and conditions.
Data Protection Policies and Governance
Internal policies, procedures, and governance structures that operationalise the principles. Article 24 requires implementation of appropriate technical and organisational measures, which may include data protection policies where proportionate to the processing.
Data Protection Impact Assessments (DPIA)
Assessments required under Article 35 where processing is likely to result in a high risk to the rights and freedoms of individuals. A DPIA is distinct from a Data Processing Agreement under Article 28; it is an assessment tool, not a contractual instrument.
Data Protection by Design and by Default
Under Article 25, controllers must embed data protection measures into processing activities and ensure that, by default, only personal data necessary for each specific purpose is processed. Evidence of these design choices supports demonstrable compliance.
Legal Basis Documentation
Records identifying the applicable Article 6 legal basis for each processing activity, and any additional Article 9 condition where special category data is involved. Demonstrating compliance includes showing that a lawful basis was identified before processing began.
Certification, Codes of Conduct and DPO Records
Approved certification mechanisms (Article 42) and codes of conduct (Article 40) may be used as elements to demonstrate compliance. Where a Data Protection Officer is appointed, records of their advice and oversight can also form part of the accountability evidence.

Common questions

Answers to the questions practitioners most commonly ask about Demonstrating Compliance With Principles.

Does documenting our data processing automatically mean we are compliant with the GDPR principles?
No. Producing documentation is not the same as demonstrating compliance. The accountability requirement generally expects a controller to show that its processing actually adheres to the principles in practice, not merely that paperwork exists. Records, policies, and assessments are evidence, but they must reflect real, operational practices and be kept accurate and up to date. Compliance is context and risk dependent, so documentation that does not correspond to what actually happens on the ground will typically not satisfy the obligation.
Is demonstrating compliance simply a one-time exercise we complete and then file away?
No. Demonstrating compliance is generally treated as an ongoing obligation rather than a single milestone. Processing activities, risks, technologies, and organisational arrangements change over time, and the evidence relied upon to show adherence to the principles typically needs to be reviewed and updated to remain meaningful. Treating it as a static, completed task risks the documentation becoming outdated and no longer reflecting actual processing, which would undermine the ability to demonstrate compliance if questioned.
What types of records or evidence can help demonstrate compliance with the principles?
In most cases, organisations rely on a combination of items such as records of processing activities, data protection policies and procedures, records of the legal basis relied upon for each processing operation, evidence of how transparency information is provided, and, where applicable, data protection impact assessments and records of consent. The appropriate mix depends on the nature, scope, context, and risk of the processing. There is no single mandated checklist that guarantees sufficiency, so the evidence should be tailored to the specific activities and reviewed for adequacy.
How should we assign responsibility internally for demonstrating compliance?
Responsibility generally sits with the controller as an organisation, but in practice it is often useful to allocate clear internal ownership for maintaining and updating the relevant records and controls. Where a data protection officer is appointed, that role typically monitors and advises on compliance rather than assuming the controller's own accountability. Roles should be defined precisely, and the distinction between a controller's obligations and any processor's obligations should be respected, since a processor's accountability duties differ from and are narrower than a controller's.
How do we keep our compliance evidence current as our processing changes?
A common approach is to build periodic review into existing governance processes and to trigger reassessment when significant changes occur, such as new processing activities, new technologies, changes in purposes, or changes in the legal basis relied upon. The frequency and depth of review should generally be proportionate to the risk of the processing. Because expectations can evolve and regulators may issue further guidance, it is advisable to verify current requirements against the applicable official text and any relevant national implementing law, which can vary.
How does the ability to demonstrate compliance relate to responding to a regulator or a data subject?
Being able to demonstrate compliance typically supports an organisation's response if a supervisory authority makes enquiries or if a data subject raises concerns, because it allows the organisation to show how its processing aligns with the principles and legal basis relied upon. However, holding evidence does not by itself resolve every question, and the sufficiency of that evidence is assessed in context. Where positions differ between regulators or remain subject to guidance, organisations should note that uncertainty and confirm the current expectations of the relevant authority.

Common misconceptions

Being compliant is enough; you do not need to prove it.
Article 5(2) frames accountability as a duty to demonstrate compliance, not only to achieve it. In most cases, a supervisory authority will expect documentary evidence, and an absence of records can itself be treated as a compliance weakness even where underlying practices are sound.
A single document, such as a privacy policy, demonstrates compliance with all principles.
Demonstrating compliance is generally a composite of measures, which may include a ROPA, DPIAs, legal basis records, and governance documentation. A public-facing privacy notice serves a transparency function and is typically not sufficient on its own to evidence accountability.
Completing a DPIA satisfies the contractual documentation required for using a processor.
A DPIA (Article 35) is a risk assessment, whereas the controller-processor relationship is governed by a Data Processing Agreement under Article 28. These are distinct instruments serving different purposes and one does not substitute for the other.

Best practices

Maintain an up-to-date Record of Processing Activities and treat it as a living document, reviewing it when processing operations change; verify whether any Article 30 exemption conditions apply to your organisation before relying on them.
Document the specific Article 6 legal basis for each processing activity, and record any additional Article 9 condition where special category data is processed, before processing commences.
Conduct and retain DPIAs for processing likely to result in high risk under Article 35, and keep evidence of any mitigation measures and the reasoning behind risk decisions.
Embed data protection by design and by default (Article 25) into new systems and projects, and keep records of the design choices and default settings adopted.
Establish clear internal governance, including policies, training records, and where applicable DPO involvement, so that accountability evidence is generated as a by-product of routine operations.
Periodically review the full set of accountability records against current official guidance, noting that regulator expectations and available tools such as approved certifications and codes of conduct may evolve over time.