Demonstrating Compliance With Principles
This refers to an organisation's ability to show, through evidence, that it is following data protection rules rather than simply claiming to do so. In addition to internal documentation, controllers can rely on tools such as codes of conduct and certification mechanisms to help evidence that they are meeting data protection principles. The relevant tools available may change over time, so organisations should check current official guidance.
The obligation on a data controller to be able to evidence its adherence to the data protection principles, an aspect of the accountability principle under the GDPR. Beyond maintaining internal records and documentation, controllers may choose to use supplementary tools such as approved codes of conduct and certification mechanisms to help demonstrate compliance with data protection principles, as noted by the European Commission. These tools are voluntary and supportive rather than exhaustive means of demonstrating compliance, and their availability and scope depend on the relevant mechanisms recognised at a given time; practitioners should verify the current position against the applicable official text and regulator guidance. Note that codes of conduct and certifications are generally supplementary evidence and do not by themselves establish full compliance, which remains context- and risk-dependent.
Why it matters
The accountability principle under the GDPR shifts the burden onto controllers: it is no longer sufficient to assert that data protection rules are being followed, an organisation must be able to evidence that adherence. Demonstrating compliance with the data protection principles is therefore central to how regulators assess an organisation's posture, and a lack of supporting documentation can undermine an otherwise sound processing activity when scrutiny arises, whether during a regulator investigation, a data subject complaint, or an audit.
Because the ability to demonstrate compliance is evidential in nature, organisations that maintain contemporaneous records and other supporting materials are generally better positioned to respond to inquiries than those relying on after-the-fact reconstruction. The European Commission notes that controllers may choose supplementary tools such as approved codes of conduct and certification mechanisms to help demonstrate compliance with data protection principles. These tools are voluntary and supportive rather than exhaustive, and adherence to a code or certification does not by itself establish full compliance, which remains context- and risk-dependent.
The practical significance is that demonstrating compliance is an ongoing exercise rather than a one-time deliverable. The specific mechanisms recognised at a given time can change, and the availability and scope of codes of conduct and certification schemes depend on the mechanisms formally recognised under the applicable framework. Practitioners should verify the current position against the applicable official text and regulator guidance rather than assume a fixed set of tools remains available or sufficient.
Who it's relevant to
Inside Demonstrating Compliance With Principles
Common questions
Answers to the questions practitioners most commonly ask about Demonstrating Compliance With Principles.