Skip to main content
Category: Privacy Principles

Lawfulness, Fairness and Transparency

Also known as: Lawful, fair and transparent processing, Principle (a)
Simply put

Lawfulness, fairness and transparency is the first data protection principle under the UK GDPR (and the EU GDPR), requiring organisations to handle personal data legally, in ways individuals would reasonably expect, and openly. Lawfulness means having a valid legal reason to process the data; fairness means not using data in ways that cause unjustified harm; and transparency means being clear with people about how their data is used. All three elements must be satisfied together, not treated as alternatives.

Formal definition

Lawfulness, fairness and transparency is the principle set out at Article 5(1)(a) of the UK GDPR and the EU GDPR governing how a controller must process personal data. Lawfulness generally requires identifying and relying on a valid lawful basis for processing (of which consent is only one option among several) and ensuring the processing does not otherwise breach the law; fairness, per ICO guidance, means handling personal data in ways individuals would expect and not using it in ways producing unjustified adverse effects; and transparency requires clear, accessible information to data subjects about the processing. These three elements overlap but are distinct requirements that must all be met, satisfying one does not discharge the others. The terms are not themselves defined in Article 4 of the GDPR, and scholarship notes they are used as distinct concepts within the instrument. This entry describes the principle at a conceptual level under UK and EU GDPR; treatment differs under other regimes such as the CCPA/CPRA or HIPAA. It does not cover the mechanics of selecting a lawful basis, transparency notice content requirements, cross-border transfers, retention, or enforcement, which are addressed under separate provisions and guidance. Note that satisfying this principle does not by itself guarantee overall compliance, which depends on the full set of principles and obligations.

Why it matters

Lawfulness, fairness and transparency is the first principle set out at Article 5(1)(a) of the UK GDPR and the EU GDPR, and it functions as a gateway requirement: an organisation that cannot demonstrate all three elements has a foundational compliance problem regardless of how well it manages other obligations. Because the three elements overlap but remain distinct, a controller cannot rely on satisfying one to discharge the others. Having a valid lawful basis does not excuse processing that individuals would not reasonably expect, and being transparent about a practice does not make an otherwise unfair or unlawful practice acceptable. This is a common expert-level trap, and treating the three as alternatives rather than cumulative requirements is a frequent source of error.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy leads use this principle as the starting point for assessing any processing activity, checking that a valid lawful basis exists, that the processing aligns with individuals' reasonable expectations, and that people are given clear information. Accountability under the GDPR requires demonstrable evidence that each of the three elements has been considered, not merely a stated intent to comply.
Compliance and legal professionals
Legal and compliance teams rely on this principle when advising on new products, marketing practices, or data uses, particularly to avoid conflating consent with the other lawful bases and to ensure that transparency measures do not become a substitute for fairness or lawfulness. Treatment differs under other regimes such as the CCPA/CPRA or HIPAA, so advice scoped to UK or EU GDPR should not be assumed to transfer.
Privacy engineers and product teams
Those designing systems that process personal data need to translate this principle into concrete choices about how data is collected, what information is surfaced to users, and whether intended uses match what individuals would expect. Because satisfying this principle alone does not guarantee overall compliance, which depends on the full set of principles and obligations, engineering decisions should be reviewed against the wider framework.

Inside Lawfulness, Fairness and Transparency

Lawfulness
The requirement that any processing of personal data rests on a valid legal basis. Under the EU GDPR and UK GDPR, the recognised lawful bases include consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest or exercise of official authority, and legitimate interests. The appropriate basis depends on the context and purpose of processing; consent is only one of several and is not inherently superior to the others. Lawfulness in this GDPR-specific sense is not framed identically across other regimes such as the CCPA/CPRA or HIPAA.
Fairness
The expectation that personal data is handled in ways individuals would reasonably expect and that do not produce unjustified adverse effects on them. Fairness concerns the substance of how data is used, not merely whether notice was given, and typically requires the controller to consider the impact of processing on the data subject.
Transparency
The obligation to inform data subjects clearly and accessibly about how their personal data is processed, generally through privacy notices and related communications. Transparency addresses whether individuals can understand what is happening to their data; it is distinct from lawfulness (whether there is a legal basis) and fairness (whether the use is justified and non-detrimental).
Controller accountability for the principle
Responsibility for applying and demonstrating adherence to lawfulness, fairness and transparency generally falls on the data controller, which determines the purposes and means of processing. A data processor acts on the controller's documented instructions and does not select the lawful basis. Accountability requires demonstrable evidence of compliance, not merely stated intent.

Common questions

Answers to the questions practitioners most commonly ask about Lawfulness, Fairness and Transparency.

Does having valid consent mean I have satisfied the lawfulness requirement?
Not necessarily. Consent is only one of several lawful bases available for processing under the EU GDPR and UK GDPR, and it should not be treated as the default or the strongest. Depending on the context, another basis such as contractual necessity, legal obligation, vital interests, public task, or legitimate interests may be more appropriate. Lawfulness requires that you identify and can justify the correct basis for each processing activity; reflexively relying on consent can create problems where consent is not freely given or can be withdrawn while the processing needs to continue. This entry addresses lawfulness as a principle and does not cover the detailed conditions attaching to each individual basis.
Is transparency just a matter of publishing a privacy notice?
A privacy notice is a common way to deliver information, but transparency as a principle is broader than the document itself. Transparency generally requires that information about processing be provided in a way that is concise, intelligible, easily accessible, and in clear and plain language, and that individuals genuinely understand what is happening with their data. A notice that is technically present but buried, vague, or misleading may not meet the standard. Transparency also interacts with fairness, since processing that surprises individuals or defeats their reasonable expectations can be unfair even where a notice exists. This answer describes the principle and does not detail the specific information categories each regime requires in a notice.
How do we decide which lawful basis applies to a given processing activity?
Selection generally starts from the purpose of the processing and the relationship with the individual, rather than from convenience. You typically map each distinct processing purpose to the basis that most accurately reflects it, considering factors such as whether the processing is necessary to perform a contract, to meet a legal obligation, or to pursue a legitimate interest that is not overridden by the individual's rights. Because a chosen basis is difficult to switch later, documenting the reasoning at the outset is advisable. This is a governance and accountability exercise; the precise conditions and any additional requirements attached to particular bases fall outside the scope of this entry.
What evidence should we keep to demonstrate compliance with this principle?
Accountability under the relevant frameworks generally requires demonstrable evidence rather than stated intent, so it is advisable to retain records that show how lawfulness, fairness, and transparency were assessed and applied. In practice this may include documentation of the lawful basis identified for each processing purpose, the reasoning behind it, versions of the information provided to individuals, and any assessments of fairness or expectations. The form and retention of such records depend on your jurisdiction and internal governance approach; this entry does not prescribe specific record-keeping obligations or retention periods.
How does fairness apply when processing is technically lawful and disclosed?
Fairness operates as a distinct requirement alongside lawfulness and transparency, so processing can satisfy a lawful basis and be disclosed yet still fall short if it is fair only in form. Fairness generally concerns whether the processing is within individuals' reasonable expectations, whether it causes unjustified adverse effects, and whether it exploits a power imbalance or uses data in ways individuals would not anticipate. Assessing fairness typically involves weighing the impact of the processing on individuals against its purpose. This entry treats fairness at the level of principle and does not address any specific automated decision-making or profiling provisions.
How do these principles apply when processing purposes change over time?
When a new or expanded purpose emerges, it is generally advisable to reassess all three aspects rather than assume the original position still holds. You typically consider whether the existing lawful basis still covers the new purpose or whether a different basis is needed, whether the change remains within individuals' reasonable expectations for fairness, and whether the information previously provided needs to be updated to preserve transparency. Changes that individuals would not expect can undermine fairness even where a lawful basis exists. This answer describes the principle-level considerations and does not cover the specific rules governing compatibility of further processing in any given regime.

Common misconceptions

Consent is required for all processing, or is the strongest lawful basis.
Consent is only one of several lawful bases under the EU and UK GDPR. In many cases another basis, such as contract, legal obligation or legitimate interests, is more appropriate. Choosing the correct basis depends on the context and purpose, and relying on consent where another basis fits better can create avoidable obligations. Consent should not be conflated with lawfulness generally.
Providing a privacy notice satisfies fairness as well as transparency.
Transparency and fairness are separate components. A notice can make processing transparent while the underlying use may still be unfair if it produces unjustified adverse effects or falls outside what individuals would reasonably expect. Meeting transparency does not by itself guarantee fairness.
Having a lawful basis on its own means the processing is compliant with the principle.
Lawfulness, fairness and transparency operate together. Identifying a valid legal basis addresses lawfulness only; the processing must also be fair and transparent. Satisfying one element does not guarantee overall compliance, which depends on context, jurisdiction and implementation.

Best practices

Identify and document the specific lawful basis for each processing activity before processing begins, rather than defaulting to consent, and record why that basis is appropriate to the purpose.
Assess whether the intended use aligns with data subjects' reasonable expectations and avoids unjustified adverse effects, treating fairness as a distinct check from having a lawful basis.
Provide clear, accessible privacy information that explains how personal data is processed, and keep it aligned with actual practice so transparency is not undermined by outdated notices.
Assign responsibility for this principle to the data controller and ensure processors act only on documented instructions, keeping the distinction between the two roles explicit.
Maintain demonstrable evidence of how lawfulness, fairness and transparency are satisfied, since accountability generally requires records rather than stated intent alone.
Where processing spans multiple regimes, scope claims to the applicable instrument and do not assume that treatment under the EU or UK GDPR carries over unchanged to frameworks such as the CCPA/CPRA or HIPAA.