Skip to main content

Rules D and E · Article 5 GDPR

Complying without being able to prove it is, before a judge, not complying

Accountability does not ask you for one more principle: it asks you for proof of all the previous ones.

There is a sentence that comes up in almost every meeting after a breach: ‘but we did do this’. It is probably true. And it is exactly as irrelevant as if it were false, because Article 5.2 of the GDPR does not assess what you do: it assesses what you can prove.

What paragraph 2 adds to paragraph 1

Article 5.1 lists the principles of processing: lawfulness, fairness, transparency, minimisation, accuracy, storage limitation. Paragraph 2 adds a duty of a different nature. It does not ask you to comply with one more principle. It asks you to be able to demonstrate that you comply with the previous ones. It is a second-order duty, and it is the one that gets lost along the way in almost every company.

SAP Asturias 412/2024, of 3 October
And, under Article 5.2 GDPR, ‘the controller shall be responsible for compliance with paragraph 1 and able to demonstrate it (accountability)’ [translation]

‘Accountability’ sounds like administrative language and is, in reality, a procedural rule: it places the burden of proof on your side. You do not arrive at trial to rebut what the other side proves. You arrive to prove your own case.

The burden of proof decides cases

In ordinary civil litigation, whoever asserts must prove. Not here. Here whoever processes the data has to prove that they processed it properly, even though nobody has proved that they processed it badly. That reversal changes the entire strategy of the case and, above all, changes when the work has to be done: beforehand.

The business consequence is uncomfortable to read and worth reading anyway. Two companies with identical actual practices can end up one acquitted and the other convicted. The only difference between them will be an orderly file.

The Madrid Provincial Court of Appeal (Audiencia Provincial de Madrid) has taken the same principle into territory where almost nobody expects it: purpose. Reading Article 5.2 together with Article 6.4, it falls to the controller to determine and demonstrate that a later purpose is compatible with the one that justified collecting the data (SAP Madrid 123/2026).

Translated into your day to day: if you use for something new some data you collected for something else — and after a breach this happens constantly, cross-checking lists to warn those affected or to clean up records — it is not enough that the new purpose strikes you as reasonable. You must have assessed it and you must be able to prove that assessment.

The accuracy principle comes with a clock

The second part of Article 5 that breaks after an incident is accuracy. It is not a decorative principle: it is a duty to act, and with an implicit deadline.

SAP Asturias 412/2024, of 3 October
Under Article 5.1(d) GDPR, data shall be accurate and, where necessary, kept up to date, which obliges controllers to take every reasonable step to ensure that inaccurate data is erased or rectified without delay [translation]

Two words rule over all the others: ‘without delay’. It does not say when the file is next reviewed. It does not say at the next update. It says without delay, that is, from the moment you know the data is inaccurate. The clock starts with knowledge, not with the complaint.

After a breach this becomes critical. Data moves, it is duplicated into working lists, it is corrected by hand, it is rectified in one system and not in the other. Every divergence that survives will be, months later, inaccurate data you kept knowingly.

Correcting without recording when and why is, for evidential purposes, not having corrected at all.

What a record that works looks like

  • Date in: when you learned the data was inaccurate, and from whom.
  • Decision: what was rectified or erased, in which systems and who authorised it.
  • Date out: when it was done, so the delay can be measured.
  • Communication: who was told about the change, inside and outside the company.
  • Closure: a record that the old data does not survive in any working list.

A table with those five columns resolves a good part of Article 5. It requires no tool at all. It requires an organisational decision: that someone is given the job, in writing, of keeping it up to date.

The same applies to the protocol and to training

Accountability does not stop at accuracy. It reaches everything you will assert on the day of the trial. Two examples that always fail: the incident response protocol and staff training.

Almost every company has ‘a procedure’. Very few have a dated document stating who decides on notification, within what deadline and with what minimum information. And almost all of them ‘train their people’, but with no attendance list and no date. Training that is not documented does not count as evidence: before a judge it is the same as not having given it.

What is at stake, in business terms

A company that can hand over its evidence file within a week negotiates. A company that needs three months to reconstruct it settles. The file does not change the substance of the case: it changes the position from which you sit down to talk, and that decides almost everything that follows.

Add an effect that appears before any litigation: your large clients are starting to ask for documentary evidence, not statements. Those who have it ready answer in days. Those who do not, delay the signature. In what a court looks at when the claim arrives are the five points where that evidence is always found missing.

Is it enough to have the policies drafted?

No. A policy with no date, no approval and no trace of application proves that somebody wrote it, not that you were complying with it. What evidences compliance is the trace of its use: decisions, records and communications.

How long must I keep that evidence?

At least for as long as someone can bring a claim against you over the facts it documents. It is worth setting this out in writing and applying it consistently, because keeping data for longer than necessary is also a failure to comply.

If you want to know at which specific points you comply without being able to evidence it, the Breach Management Test flags them one by one, with the applicable rule.

Check what you could prove tomorrow

We do not assess your systems. We assess whether you could prove before a court what your company already does every day.

Take the Breach Management Test
articulos/art5-2-responsabilidad-proactiva
Article 5.2 GDPR: complying is not enough, prove it | ILP Abogados