Skip to main content
Category: Data Quality

Accuracy

Simply put

Accuracy is how closely a value matches the true or correct value it is meant to represent. In a measurement context, it describes freedom from error and conformity to a known standard, and is distinct from precision, which describes how closely repeated measurements agree with one another. The evidence provided defines accuracy in a general and metrological sense rather than as a specific data protection principle.

Formal definition

Accuracy is the degree of conformity between an observed or recorded value and the true or accepted reference value of the quantity being assessed, and is generally established by calibration against a known standard. It should not be conflated with precision, which measures the closeness of multiple measurements to each other rather than to a true value; a set of results can be precise without being accurate, and vice versa. Note that the evidence supplied here frames accuracy in metrological and general terms and does not address how accuracy is treated as a data protection or data-quality principle under any specific legal or standards instrument (for example, obligations to keep personal data accurate and up to date under a given data protection regime), nor does it cover related governance concerns such as data lineage, correction or rectification processes, or retention. Those regime-specific treatments are out of scope for this entry based on the available evidence.

Why it matters

Accuracy underpins whether any data-driven decision, measurement, or record can be trusted. A value that does not correspond to the true state it purports to represent can propagate errors downstream, undermining analysis, reporting, and operational decisions that depend on the record being correct. Because accuracy is defined as conformity to a true or accepted reference value, an organisation cannot assume its data is accurate simply because it is consistent; the evidence here makes clear that a set of results can be precise without being accurate, and vice versa.

This distinction matters in practice because teams frequently conflate the two. Repeated agreement between measurements (precision) can create false confidence that values are correct, when in reality a systematic offset may be pushing every measurement uniformly away from the true value. Recognising accuracy as a separate property forces the question of what the correct reference value actually is, and how conformity to it is established.

The evidence supplied frames accuracy in a general and metrological sense. It does not address how accuracy operates as a data protection principle, such as any obligation to keep personal data accurate and up to date under a particular regime, nor does it cover related governance mechanisms like rectification, lineage, or retention. Readers should treat those regime-specific treatments as out of scope for this entry rather than assume the metrological framing extends to legal obligations.

Who it's relevant to

Data governance and data quality leads
Those responsible for data quality need to treat accuracy as conformity to a true or accepted reference value, distinct from consistency or repeatability. This entry provides the general and metrological grounding for that distinction, but it does not cover data-quality obligations, lineage, correction processes, or retention under any specific governance framework, which should be sourced separately.
Analysts and professionals working with measurement data
Anyone interpreting measurements should distinguish accuracy from precision to avoid mistaking closely agreeing results for correct ones. The evidence emphasises that a set of measurements can be precise without being accurate, so calibration against a known standard is central to establishing accuracy.
Privacy and compliance practitioners
Practitioners looking for how accuracy operates as a data protection principle, for example any obligation to keep personal data accurate and up to date, will not find that treatment here. The available evidence addresses accuracy only in a general and metrological sense; regime-specific requirements are out of scope for this entry and must be confirmed against the applicable instrument.

Inside Accuracy

Accuracy Principle
A core data protection principle, expressed in instruments such as the EU GDPR and UK GDPR, generally requiring that personal data be accurate and, where necessary, kept up to date. It is one of several principles and does not on its own guarantee overall compliance.
Reasonable Steps to Correct or Erase
The expectation that a controller takes reasonable steps to ensure that personal data which is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without undue delay. What is reasonable typically depends on the purpose and context of processing.
Purpose-Relative Standard
Accuracy is assessed relative to the purpose of processing rather than as an absolute state. Data adequate for one purpose may be insufficiently accurate for another, so the standard is contextual.
Link to the Right to Rectification
In regimes such as the EU GDPR and UK GDPR, data subjects generally have a right to have inaccurate personal data rectified. Handling such requests operationalizes the accuracy principle, though rectification mechanics and exceptions differ by regime and are only partially covered here.
Controller Accountability
Responsibility for maintaining accuracy generally rests with the data controller, who determines the purposes and means of processing. A processor typically acts on the controller's documented instructions and does not independently bear this obligation. Accountability requires demonstrable evidence, not merely stated intent.
Governance versus Security Distinction
Accuracy is primarily a data governance and data quality concern (ownership, stewardship, lineage, correction processes) rather than an information security concern. It overlaps with integrity controls where security measures help prevent unauthorized or unintended alteration, but accuracy and integrity are not the same thing.

Common questions

Answers to the questions practitioners most commonly ask about Accuracy.

Does the accuracy principle mean an organisation must guarantee that all personal data it holds is correct at all times?
No. The accuracy principle, as expressed in instruments such as the EU GDPR and UK GDPR, generally requires that personal data be accurate and, where necessary, kept up to date, and that reasonable steps be taken to erase or rectify inaccurate data without delay. This is an obligation of reasonable effort proportionate to the purpose of processing, not an absolute guarantee that no error will ever exist. What counts as reasonable typically depends on the purpose, the nature of the data, and the potential impact of inaccuracy on the individual. This answer does not address retention rules or the mechanics of responding to rectification requests, which are treated separately.
Is accuracy purely a data governance concern about data quality, or is it also a legal obligation?
It is both, and the two should not be collapsed. As a data governance matter, accuracy overlaps with data quality practices such as stewardship, validation, and lineage. As a legal matter under regimes such as the EU GDPR and UK GDPR, accuracy is a distinct principle carrying accountability obligations that generally require demonstrable evidence of the steps taken, not merely stated intent or a documented policy. The governance activity supports the legal obligation but is not a substitute for it. Treatment differs across jurisdictions, and this entry does not cover how other regimes such as the CCPA and CPRA or HIPAA frame data quality.
What reasonable steps can an organisation take to keep personal data accurate?
Reasonable steps typically include validation at the point of collection, periodic review appropriate to the purpose, mechanisms for individuals to notify or request corrections, and processes to propagate corrections to downstream systems and any processors acting on the controller's instructions. What is reasonable is proportionate to the purpose and the risk to individuals; there is generally no single prescribed set of controls. This answer does not address cross-border transfer mechanics or retention scheduling.
Who bears responsibility for accuracy when a processor handles the data?
Under the controller and processor distinction in regimes such as the EU GDPR and UK GDPR, the controller generally bears the primary obligation for the accuracy of personal data, since the controller determines the purposes and means of processing. A processor typically acts on the controller's documented instructions, which may include correcting or updating data on request. Contractual arrangements usually specify how rectification is handled between the parties. This entry does not detail the full allocation of contractual obligations.
How should an organisation demonstrate that it has met the accuracy principle?
Because accountability under these frameworks generally requires demonstrable evidence rather than stated intent, an organisation would typically retain records of its validation processes, review cycles, correction workflows, and how it responds to identified inaccuracies. Such evidence supports, but does not by itself guarantee, compliance, which depends on context, jurisdiction, and implementation. This answer does not address enforcement outcomes or penalties.
How should accuracy be handled when data is transferred to downstream or connected systems?
When corrections are made, a practical approach is generally to identify all systems and any processors holding copies of the data and to propagate the correction so that inaccurate versions are not retained or acted upon. This depends on maintaining knowledge of data flows, which is where governance practices such as data lineage support the accuracy obligation without being equivalent to it. This entry does not cover the mechanics of specific integration or synchronisation tooling.

Common misconceptions

Accuracy requires that all personal data be complete and up to date at all times.
The requirement is generally qualified by the phrase 'where necessary' and is assessed relative to the purpose of processing. Data need only be as accurate and current as the specific processing purpose requires, not perfect in every respect.
The accuracy principle is the same as the security integrity control that protects data from unauthorized modification.
Accuracy is a governance and data quality obligation about whether data correctly reflects reality for its purpose, while integrity is an information security property concerning confidentiality, integrity, and availability. They overlap but are distinct; strong integrity controls do not by themselves satisfy accuracy.
Because a processor stores or manipulates the data, it is responsible for keeping that data accurate.
Responsibility for accuracy generally sits with the controller, who determines purposes and means. A processor typically acts only on documented instructions and does not independently carry the accuracy obligation, though contractual arrangements may allocate supporting tasks.

Best practices

Define accuracy standards per processing purpose rather than pursuing a single absolute standard, and document why a given level of accuracy is necessary for each use.
Establish clear data ownership and stewardship so that a named party is accountable for correcting or erasing inaccurate personal data without undue delay.
Build a repeatable process to handle rectification requests and to propagate corrections across systems, retaining demonstrable evidence that reasonable steps were taken.
Distinguish accuracy (governance and data quality) from integrity controls (security) in your policies, while using security measures to guard against unintended alteration where relevant.
Clarify controller and processor roles contractually, ensuring the controller retains accountability for accuracy and that processors act on documented instructions.
Treat this control as one element among several data protection principles, and validate overall compliance against the applicable regime rather than assuming accuracy alone is sufficient.