← Compliance guide

Principles and lawful grounds

The ground rules for handling personal data, and the reasons the law accepts for handling it at all.

Article 5

Principles relating to processing of personal data

What it asks for

Personal data must be handled lawfully, fairly and openly, collected for stated purposes, limited to what is needed, kept accurate, kept no longer than necessary and kept secure. The organisation must also be able to demonstrate all of that.

For example

A shop collects an email address to send a receipt. Using the same address for a newsletter is a new purpose and needs its own justification.

How Prudence covers it

Every processing activity records its purpose, the data it uses, who it concerns and how long it is kept. The word demonstrate in Article 5(2) is the reason Prudence keeps an unalterable history of every change.

Still yours to decide: Deciding whether a purpose is fair and necessary is a management decision.

Article 6

Lawfulness of processing

What it asks for

Each processing operation needs one of six lawful bases: consent, a contract, a legal duty, vital interests, a public task, or a legitimate interest that does not override the rights of the data subject.

For example

Paying an employee relies on the employment contract. Sending that employee a marketing survey does not, and needs a different reason.

How Prudence covers it

A processing activity cannot leave draft status without a lawful basis chosen from the six. Choosing legitimate interests prompts for the balancing assessment that Article 6(1)(f) implies.

Article 7

Conditions for consent

What it asks for

Where consent is the reason, the organisation must be able to show the person agreed, ask in clear separate wording, and make withdrawal as easy as giving it.

For example

A website tick box that is already ticked is not consent. A record of who ticked it, when, and against which wording, is what proves the point later.

How Prudence covers it

The consent register stores the wording version, the method, the date and the withdrawal route for each consent. A consent with no recorded wording version is raised as a gap.

Article 8

Conditions applicable to child's consent

What it asks for

Where an online service is offered directly to a child, consent below the national age limit, between thirteen and sixteen, must come from the holder of parental responsibility.

For example

A homework help site aimed at fourteen year olds needs parental authorisation in a member state where the limit is sixteen.

How Prudence covers it

Consent records carry the age group and, where a child is involved, the verification method used. Prudence raises a gap when a child consent has no verification recorded.

Article 9

Processing of special categories of personal data

What it asks for

Health data, biometrics, ethnicity, religion, trade union membership, political opinions and data about sex life are prohibited unless one of ten conditions applies. This is a second requirement on top of Article 6, not a replacement for it.

For example

A clinic keeps patient notes. The contract with the patient supports Article 6. The condition for healthcare provision in Article 9(2)(h) is also needed.

How Prudence covers it

Marking an activity as involving a special category makes the Article 9 condition a required field, and the activity cannot go live without it.

Article 10

Criminal convictions and offences

What it asks for

Data about criminal convictions and offences may only be handled under official authority or where a member state law allows it. It is a separate regime from Article 9.

For example

A security firm running background checks on staff needs a national legal provision permitting it, not simply the candidate's agreement.

How Prudence covers it

Prudence treats criminal offence data as its own category with its own field for the authorising national provision, so it is never confused with special category data.

Article 11

Processing not requiring identification

What it asks for

If the organisation genuinely cannot identify the people behind the data, it does not have to collect more data purely to comply, but it must say so when a person asks.

For example

A visitor counter that stores no identifiers cannot connect a request to a particular visitor.

How Prudence covers it

An activity can be marked as not requiring identification, which changes the rights guidance shown against it.