> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What Does "Accountability" Mean Under the GDPR?
- URL: https://www.thedelatorrereview.com/what-does-accountability-mean-under-the-gdpr/
- Published: 2020-01-22T17:31:00.000Z
- Updated: 2026-07-11T17:51:25.000Z
- Description: The GDPR requires controllers not only to comply with the Regulation but also to demonstrate that compliance. This article examines the obligation in light of Recitals 39 and 74, showing how governance, documentation, and oversight make accountability a legal duty.
- Author: Lydia
- Tags: Accountability, Principles, GDPR, EU, Data Protection Law, Data Protection Impact Assessment (DPIA) / Privacy Impact Assessment (PIA), Privacy by Design

There are seven basic data protection principles under EU data protection law. The seventh principle is the principle of “accountability” (GDPR Article 5 (2)).

---

> Article 5 of GDPR

2\. The controller shall be responsible for, and be **able to demonstrate**compliance with, paragraph 1 (‘accountability’).

\[See also Articles 77, 82 and 83 of GDPR\]

---

The accountability principle requires controllers and processors to take responsibility for their processing activities and for how they comply with data protection principles. Having appropriate measures and records in place to demonstrate your compliance is key.

There are two key elements to accountability.

1. First, the accountability principle makes it clear that controllers and processors are **responsible** for complying with the GDPR.
2. Second, controllers and processors must be able to **demonstrate** compliance.

Accountability is not a box-ticking exercise. Being **responsible** for compliance means being proactive and organised about data protection, while **demonstrating** compliance is the ability to present evidence of the steps taken to comply. To achieve this, larger organisations need to put in place a management framework which can help create a culture of commitment to data protection. The framework should include:

- robust program controls informed by the requirements of the GDPR;
- appropriate reporting structures; and
- assessment and evaluation procedures.

Smaller organizations can take smaller scale approach to accountability but must:

- ensure a good level of understanding and awareness of data protection among staff;
- implement comprehensive but proportionate policies and procedures; and
- keep records.

Measures that can help support an accountable approach to data protection include:

- Ensuring security measures are in place (Article 24(1), Article 32 and Recitals 39 and 83 GDPR)
- Issuing and implementing data protection policies where appropriate (see Article 24(2) and Recital 78 GDPR)
- Adopting data protection by design and by default (Article 25 and Recital 78 GDPR)
- Formalizing appropriate contracts with processors and sub-processors (Article 28 and Recital 81 GDPR)
- Maintaining appropriate documentation of processing activities (Article 7(1), 30, and 33(5) plus Recitals 42 and 82 GDPR)
- Recording and reporting data breaches (Article 33–34 and Recitals 85–88 GDPR)
- Carrying out data protection impact assessments (DPIAs) where required (Article 35036 and Recitals 84 and 89–95 GDPR)
- Assigning a data protection officer (DPO) where required (Article 37–39 and Recital 97 GDPR)
- Adhering to codes of conduct and certification schemes where appropriate (Article 40–43 and Recitals 98 and 100 GDPR)

The key is to be able to prove what steps were taken to comply which in practice means keeping records of what has been done and justifying the decisions taken.

> **Example:** A company wants to use the personal data it holds for a new purpose. It carries out an assessment in line with Article 6(4) of the GDPR, and determines that the new purpose is compatible with the original purpose for which it collected the personal data. Although this provision of the GDPR does not specify that the company must document its compatibility assessment, it knows that to be accountable, it needs to be able to prove that their handling of personal data is compliant with the GDPR. The company therefore keeps a record of the compatibility assessment, including its rationale for the decision and the appropriate safeguards it put in place.

Accountability **is not just about answering to a regulator: organizations must also demonstrate compliance to individuals.** The obligations that accountability places are ongoing and steps must be reviewed at appropriate intervals to ensure that they remain effective.

### Leadership and oversight

Accountability begins with effective leadership and oversight. Controllers and processors should assign overall responsibility for data protection at the highest appropriate level of the organization and ensure that privacy considerations are embedded into governance and decision-making. Roles, responsibilities, reporting lines, and oversight mechanisms should be clearly defined in policies and reflected in organizational structures, job descriptions, and governance processes. Individuals responsible for data protection should have sufficient authority, resources, and direct access to senior management to perform their responsibilities effectively.

Strong leadership also requires fostering a culture in which data protection is viewed as a shared organizational responsibility rather than solely a legal or compliance function. Senior management should lead by example, ensure that employees understand their respective responsibilities, and periodically review whether governance arrangements remain effective as the organization evolves. Regular assessments of reporting lines, policies, training, and oversight mechanisms help demonstrate accountability and support continuous compliance with the GDPR.

## Policies and Procedures

Documented policies and procedures are essential to demonstrating accountability under the GDPR. Organizations should adopt a coherent policy framework that reflects their governance strategy and addresses the full lifecycle of personal data, including data protection, information security, records management, incident response, and other relevant compliance areas. Policies should clearly define responsibilities, provide practical guidance for employees, and be readily accessible to all personnel whose roles involve the processing of personal data. Where specialized functions exist, organizations should supplement general policies with role-specific procedures and operational guidance.

Policies and procedures should be subject to formal governance and document control. They should follow a consistent format, identify an owner, include version control and review dates, and be reviewed periodically or whenever legal, regulatory, or operational changes require updates. Organizations should also ensure that policies are appropriately approved by senior management and communicated effectively throughout the organization. Employees should understand not only where to find applicable policies, but also how those policies affect their day-to-day responsibilities.

Finally, policies and procedures should embed **data protection by design and by default** into organizational processes. Privacy considerations should be incorporated into the design of new systems, products, services, and business practices from the outset, rather than addressed only after implementation. Policies should reinforce the GDPR principles—including data minimization, purpose limitation, security, and accountability—and, where appropriate, require the use of privacy-enhancing technologies, risk assessments, and additional safeguards for vulnerable individuals such as children. Regular reviews and internal audits can help ensure that policies remain effective and are consistently followed in practice.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-11--2026-at-10_45_53-AM.png)

### ICO Checklist

The [Information Commissioner’s Office](https://ico.org.uk/?ref=thedelatorrereview.com) website includes a helpful Checklist that summarizes this principle:

![](https://cdn-images-1.medium.com/max/800/0*i3b2DagSZOTvfcen)

### Consequences of non-compliance

---

Failure to comply with data protection principles may lead to substantial fines. Article 83(5)(a) of GDPR states that infringements of the basic principles for processing personal data are subject to the highest tier of administrative fines. This could mean a fine of up to €20 million, or 4% of your total worldwide annual turnover, whichever is higher.

### Additional Resources

Recitals: [(39) Principles of Data Processing](https://gdpr-info.eu/recitals/no-39/?ref=thedelatorrereview.com) [(74) Responsibility and Liability of the Controller](https://gdpr-info.eu/recitals/no-74/?ref=thedelatorrereview.com)

Office of the DP commissioner of Guernsey: [Guidelines on the principle of accountability](https://odpc.gg/wp-content/uploads/2018/03/Accountability.pdf?ref=thedelatorrereview.com) (2018)

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/Screenshot-2026-07-04-at-4.45.19---PM-44.png)