Lawfulness, Fairness and Transparency
Lawfulness, fairness and transparency is the first data protection principle under the UK GDPR (and the EU GDPR), requiring organisations to handle personal data legally, in ways individuals would reasonably expect, and openly. Lawfulness means having a valid legal reason to process the data; fairness means not using data in ways that cause unjustified harm; and transparency means being clear with people about how their data is used. All three elements must be satisfied together, not treated as alternatives.
Lawfulness, fairness and transparency is the principle set out at Article 5(1)(a) of the UK GDPR and the EU GDPR governing how a controller must process personal data. Lawfulness generally requires identifying and relying on a valid lawful basis for processing (of which consent is only one option among several) and ensuring the processing does not otherwise breach the law; fairness, per ICO guidance, means handling personal data in ways individuals would expect and not using it in ways producing unjustified adverse effects; and transparency requires clear, accessible information to data subjects about the processing. These three elements overlap but are distinct requirements that must all be met, satisfying one does not discharge the others. The terms are not themselves defined in Article 4 of the GDPR, and scholarship notes they are used as distinct concepts within the instrument. This entry describes the principle at a conceptual level under UK and EU GDPR; treatment differs under other regimes such as the CCPA/CPRA or HIPAA. It does not cover the mechanics of selecting a lawful basis, transparency notice content requirements, cross-border transfers, retention, or enforcement, which are addressed under separate provisions and guidance. Note that satisfying this principle does not by itself guarantee overall compliance, which depends on the full set of principles and obligations.
Why it matters
Lawfulness, fairness and transparency is the first principle set out at Article 5(1)(a) of the UK GDPR and the EU GDPR, and it functions as a gateway requirement: an organisation that cannot demonstrate all three elements has a foundational compliance problem regardless of how well it manages other obligations. Because the three elements overlap but remain distinct, a controller cannot rely on satisfying one to discharge the others. Having a valid lawful basis does not excuse processing that individuals would not reasonably expect, and being transparent about a practice does not make an otherwise unfair or unlawful practice acceptable. This is a common expert-level trap, and treating the three as alternatives rather than cumulative requirements is a frequent source of error.
Who it's relevant to
Inside Lawfulness, Fairness and Transparency
Common questions
Answers to the questions practitioners most commonly ask about Lawfulness, Fairness and Transparency.