2. Principles
Storage limitation, security and accountability
Storage limitation
Don't keep personal data for longer than you need it. This means having, and following, a retention schedule, and actually deleting or anonymising data once its purpose has been fulfilled.
Integrity and confidentiality (security)
Process data securely, using appropriate technical and organisational measures, protecting against unauthorised or unlawful processing, and against accidental loss, destruction, or damage.
Accountability
You are responsible for complying with the other six principles, and you must be able to demonstrate that compliance, for example through documentation, policies, training records, and a record of processing activities (ROPA). "We probably do that" is not accountability; a written record is.
Check your understanding
A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.
Try the section quiz →› Course contents
Principles
Rights of the individual
Legal bases for processing