Accountability Under the GDPR: How Companies Prove Their Compliance

The accountability principle under Article 5(2) GDPR requires companies not only to ensure compliance with the data protection principles but to actively be able to prove it. This proof consists of concrete documents: a record of processing activities (Article 30), documented technical and organizational measures (Article 32), data processing agreements (Article 28), and training records. If proof is missing, the rule in case of doubt is: not done.
From the Provimedia editorial team · As of July 2026 · This article is general information and not legal advice.
What Does Accountability Mean Under Article 5(2) GDPR?
Article 5(2) GDPR sets out a single but far-reaching sentence: the controller is responsible for complying with the six principles from paragraph 1 and must be able to prove that compliance ("accountable"). This sets the GDPR apart from many older data protection rules: it is not enough to behave in a data-protection-compliant way. In a real case, for example during a supervisory authority inspection, after a data breach, or in response to a complaint, a company must be able to demonstrate that it followed the rules.
In practice, this means documentation is not bureaucracy for its own sake but the actual obligation itself. Anyone who documents nothing has nothing to show in a dispute, even if everything internally was done correctly.
What Exactly Must You Be Accountable For?
The accountability principle refers to the six principles from Article 5(1) GDPR, which every data processing activity must satisfy at the same time:
- Lawfulness, fairness, and transparency: requires a legal basis and openness toward data subjects.
- Purpose limitation: use data only for the purpose for which it was collected.
- Data minimization: only as much data as necessary.
- Accuracy: data must be factually correct and up to date.
- Storage limitation: keep data only as long as it is needed.
- Integrity and confidentiality: adequate protection against loss and unauthorized access.
For each of these principles, a company must be able to show, in case of doubt, how it implements it, not just claim that it observes it.
Which Records Count in Practice?
The GDPR does not prescribe a single checklist of records, but in practice a core set of documents has become established, derived from various individual provisions:
| Record | Legal Basis | What It Proves |
|---|---|---|
| Record of processing activities (ROPA, in German: Verzeichnis von Verarbeitungstätigkeiten, VVT) | Art. 30 GDPR | Which data processing activities exist, for what purpose, and on what legal basis. |
| Technical and organizational measures (TOMs) | Art. 32 GDPR | How data is protected technically and organizationally. |
| Data processing agreements (DPAs, in German: Auftragsverarbeitungsverträge, AVV) | Art. 28(3) GDPR | That external service providers are contractually bound to data protection. |
| Proof of consent | Art. 7(1) GDPR | That consent was actually given and can be demonstrated. |
| Employee training records | Art. 39(1)(b) GDPR | That staff were made aware of and trained in data protection. |
| Data protection impact assessment (for high risk) | Art. 35 GDPR | That risks were assessed before introducing new, risky processing activities. |
The training record is not a side issue here: Article 39(1)(b) explicitly names "awareness-raising and training of staff involved in processing operations" as a task monitored as part of the data protection organization. A documented, dated participation in a training course is therefore a concrete, verifiable building block of accountability, regardless of whether a dedicated data protection officer has been appointed.
What Happens if You Cannot Prove Anything?
Violations of the principles in Article 5 GDPR, including the accountability obligation from paragraph 2, fall into the upper fine category: up to 20 million euros or 4% of worldwide annual turnover, whichever amount is higher (Article 83(5) GDPR).
What determines the actual amount in an individual case includes, among other things, the severity and duration of the violation as well as the technical and organizational measures taken by the controller (Article 83(2) GDPR). A company that has demonstrably taken precautions is in a better position when the fine is assessed than one with no documentation at all. These figures are a statutory framework, not a forecast for every individual case: they show why the ability to provide proof is more than mere formalism.
Four Steps to Demonstrable Accountability
- Take stock: what personal data do you process, for what purpose, with which service providers? This is the basis for the ROPA.
- Create the documents: create or update the ROPA, the TOM overview, and the DPAs with all relevant service providers.
- Train staff and secure the proof: a dated participation confirmation per person closes the documentation gap addressed by Article 39(1)(b).
- Keep it current: update documents and training whenever new tools, new service providers, or legal changes arise.
A digital training program efficiently covers step 3. Our GDPR fundamentals training for employees can be booked online and delivers exactly this dated, QR-verifiable record per person; the AI certificate complements it with a documented building block for the AI literacy requirement under Article 4 of the EU AI Act.
Frequently Asked Questions (FAQ)
What Is the Accountability Principle Under the GDPR?
The obligation under Article 5(2) GDPR to not only ensure compliance with the six data protection principles from Article 5(1) but to actively be able to prove it, for example to a supervisory authority.
Which Records Do I Specifically Need?
In practice, mainly a record of processing activities (Article 30), documented TOMs (Article 32), data processing agreements (Article 28), and records of employee training (Article 39(1)(b)).
Is a Training Participation Certificate Enough as Proof?
A participation certificate proves that a person was trained. This is a single but recognized building block of accountability. It does not replace the other records such as the ROPA or DPAs, and it is not an official GDPR certification of the company.
What Is at Risk Without Sufficient Proof?
Violations of the principles in Article 5 GDPR can be punished with fines of up to 20 million euros or 4% of worldwide annual turnover (Article 83(5) GDPR). The actual amount depends on the individual case, including the protective measures taken.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 5, Art. 7(1), Art. 28(3), Art. 30, Art. 32, Art. 35, Art. 39(1)(b), Art. 83(2) and (5): eur-lex.europa.eu
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Phishing and Social Engineering: How Your Employees Can Spot an Attack
Phishing, spear phishing, CEO fraud, and smishing target people, not systems. The warning signs a phishing employee training should teach, and why a successful attack quickly turns into a reportable data breach.
GDPR Fines: Real Cases from Germany and What Companies Can Learn from Them
Four real GDPR fine cases from Germany show how authorities calculate the amount, and that courts can also significantly reduce them afterward.
Information Security Training vs. GDPR Training: What Companies Actually Need
Information security protects systems and information, data protection protects people and their data. The difference, the overlap under Art. 32 GDPR, and what the new NIS2 training duty means for management boards.
Bereit für den dokumentierten Schulungsnachweis?
Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.