Insight into Accountability GDPR

Insight into Accountability GDPR in the UK

Underpinning the General Data Protection Regulation (‘GDPR’) are several data protection principles which ensure compliance in relation to the processing of an individual’s personal data. These principles are broadly similar to the existing principles under the Data Protection Act 1998 (‘DPA’). A significant change introduced by the GDPR is the new principle of accountability. This principle creates an onus on organisations to understand the risks that they create in relation to processing and to mitigate those risks.

What is the accountability principle?

The GDPR elevates the significance of accountability and expressly introduces the concept of accountability as an independent data protection principle. Article 5 (2) of the GDPR provides that ‘the controller shall be responsible for, and be able to demonstrate, compliance with the principles.’

Responsibility for Compliance

The GDPR explicitly places direct responsibility for compliance with the data protection principles on organisations processing personal data and further requires the organisations to show compliance in order to minimise the risk of breaches and upholds the protection of personal data. 

How can you can show that you comply?

To comply with the principle of accountability, you should put in place comprehensive and appropriate governance measures. The appropriateness of measures will depend on the nature, scope, context and purposes of the relevant processing and taking into account the risk to the rights and freedoms of individual. 

Measures for Implantation

The Information Commissioner (‘ICO’) suggests implementing some of the following measures:

  • Appointing a Data Protection Officer to monitor compliance, where appropriate;
  • Implementing appropriate technical and organisational measures in relation to processing activities i.e.
    • Internal data protection policies such as staff training
    • Internal audits of processing activities
    • Reviews of internal HR policies

Reviewing and Updating

Any measures that are put in place will need to be periodically reviewed and updated, as appropriate. 

  • Maintaining relevant documentation on processing activities, in particular if organisations that employ more than 250 people are required to maintain internal records of data processing activities which are to be made available to supervisory authorities on request. If you have less than 250 you will be required to maintain records of higher risk processing activities;
  • Implementing measures that meet the principles of data protection by design and data protection by default measures to show that the principles have been taken into account and incorporated into your activities, for example:
    • Data minimisation of personal data that is adequate, relevant and necessary
    • Pseudonymising of data to reduce links with the identity of the individual
    • Transparency
    • Allowing individuals to monitor processing
    • Creating and improving security features on an ongoing basis
  • Using data protection impact assessments (‘DPIA’) where an organisation uses new technologies or where the processing is likely to result in a high risk to the rights and freedoms of the individual.

You can also:

  • Adhere to approved codes of conduct and/or certification schemes to demonstrate compliance

Of course, what is appropriate for your organisation will depend on the circumstances and it is important that businesses do not fall into the trap of just doing what everyone else does. We are able to assist you in determining what your specific needs are so that your compliance (and ability to show your compliance) is maximised.

Consequences of not complying with accountability

Failure to comply with the requirements of the GDPR and in particular, the accountability requirement, could result in a maximum fine of up to EUR 20 million or 4% of the organisation’s worldwide annual revenue for the preceding financial year, whichever is higher. As the potential financial ramifications of non-compliance are substantial, we would advise ensuring full compliance with the GDPR.

Systematic and Proactive Approach to GDPR

  • Now the GDPR is in force we would advise taking a systematic and proactive approach in preparation for the GDPR in relation to how you process personal data to demonstrate data protection compliance. It is essential to: 
    • Review any existing policies and procedures to assess how the GDPR will affect your organisation
    • Update any policies and procedures relating to the processing of personal data
    • implement appropriate measures to ensure compliance with the GDPR is adhered to

Chartergates can help you navigate your way through your obligations under the GDPR to ensure full compliance. If you require any help or assistance, contact us now.

DISCLAIMER – This fact sheet has been produced by Chartergate Legal Services Limited as a general overview of the law. It is no substitute for specific professional advice given on the basis of your own circumstances and should not be relied on as such.

GDPR Accountability FAQ

What is the accountability principle under GDPR?

The accountability principle requires organisations to take responsibility for how they process personal data and to be able to demonstrate compliance with GDPR. It is set out in Article 5(2) and applies to all organisations acting as data controllers.
The organisation that processes personal data is responsible for compliance. This includes ensuring that appropriate measures are in place and being able to evidence those measures if required by regulators such as the ICO.
Organisations can demonstrate compliance by implementing clear governance measures. This includes documented policies, staff training, internal audits, and maintaining records of processing activities.
Not all organisations need a DPO. However, one should be appointed where required, such as when large-scale processing of sensitive data takes place or where monitoring activities are extensive.

Examples include:

  • Data protection policies and staff training
  • Regular audits and reviews of data processing
  • Data protection impact assessments (DPIAs)
  • Security measures such as encryption or pseudonymisation
  • Data protection by design and by default
This means embedding data protection into processes from the start. Organisations should only collect and process the minimum amount of personal data necessary and ensure strong privacy settings are in place automatically.
Yes, but requirements vary. Organisations with fewer than 250 employees may not need full records unless they process high-risk data. Larger organisations must maintain detailed records of all processing activities.
A DPIA is a risk assessment used when processing is likely to result in a high risk to individuals. It helps identify and minimise data protection risks before starting new projects or technologies.
Non-compliance can lead to significant fines. Penalties can reach up to €20 million or 4% of global annual turnover, whichever is higher, depending on the severity of the breach.
GDPR measures should be reviewed regularly. This ensures policies remain up to date, risks are managed effectively, and compliance can be maintained as business activities evolve.
Yes, adhering to approved codes of conduct or certification schemes can help show that your organisation meets GDPR standards and takes accountability seriously.
Chartergates can assess your current processes, identify risks, and implement tailored compliance measures. This ensures your organisation not only meets GDPR requirements but can clearly demonstrate accountability.

Disclaimer: Chartergate Legal Services Ltd has drafted these FAQs to provide a general overview of the relevant law only.  These FAQs are not a substitute for professional advice that is specific to your circumstances and should not be relied upon as such.

Popup 3
Popup 2
Popup 1