Data Accuracy: The Fourth GDPR Privacy Principle

Data accuracy – keeping accurate personal data are essential for lawful, fair and effective data processing and decision making. The Accuracy Principle is often overlooked because it appears deceptively simple. Many organisations reduce it to “keep records up to date.” In reality, it is about ensuring that decisions are based on reliable information and recognising that inaccurate personal data can have serious consequences for individuals and organisations.

Accuracy is proportionate. Not every piece of personal data requires continual updates, but organisations should take reasonable steps to ensure information is correct and rectify inaccuracies promptly. Every decision an organisation makes about an individual is only as good as the information on which it is based. Whether recruiting staff, treating patients, paying employees or communicating with customers, organisations rely on accurate personal data. The accuracy principle helps ensure those decisions are fair, reliable and based on information that reflects reality.

Key Messages

  • Personal data should be accurate and, where necessary, kept up to date.
  • Organisations should take reasonable steps to correct inaccurate information.
  • The level of accuracy required depends on the purpose of the processing.
  • Poor-quality data can lead to poor decisions, regulatory breaches and loss of trust.

The Text of the Principle

Article 5(1)(d) reads that “Personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.”

The principle recognises that accuracy is not static. Organisations must maintain information appropriately and correct inaccuracies when they are identified. This means also having the right mechanisms to check accuracy from time to time and update personal data when necessary.

 

Periodic Table of the GDPR

 

What Does the Principle of Data Accuracy Mean?

The principle has three elements:

Accurate

Information should correctly reflect the facts. This applies to both objective data like name, address or data of birth, but also subjective data such as opinions.

Kept Up to Date Where Necessary

Information should be reviewed and updated when necessary. This is because information about people can change over time, or because the purpose for which the data is collected may change.

Rectified Without Delay

When inaccuracies or gaps are identified, organisations should take reasonable steps to correct them promptly. If the data cannot be correct or updated organisations should consider deleting it.

Overall the principle seeks to ensure data is fit for purpose and organisations do not risk causing harm to themselves or data subjects by using inaccurate or out of data information. It’s important to reflect on what “every reasonable step” means. If you process data that changes rapidly, or will get out of date quickly, then you need to take further steps than otherwise. The rate at which data goes out of date is sometimes called “data decay” and will vary from company to company.

For example:

  • children’s data gets out of date more quickly than that of adults;
  • lists of customers who have bought from your store once only has a limited shelf-life;
  • some sensitive classes of data, like medical information, need greater scrutiny for accuracy and currentness compared to other, less, sensitive classes.

 

Why Data Accuracy Matters

The practical importance of accurate personal data goes beyond GDPR compliance. Operationally being able to rely on the data you have collected brings a range of benefits.

Better Decision-Making

Reliable information supports fair and informed decisions. All organisations rely on timely high quality data to make and implement strategic decisions. Duplicate records, typos, or outdated contact details forces people to spend time cleaning up data or correcting errors in downstream systems.

Protecting Individuals

Inaccurate information can result in financial loss, discrimination, inconvenience or reputational damage. For example, a bank sending important financial documents to a customer’s previous address.

Improved Service Delivery

Correct information helps organisations communicate effectively and deliver services efficiently. For example, sending out a marketing campaign to a stale list of email contacts will result in more bounce-backs and less engagement than a fresher contact list. Up-to-date data ensures that organisations can provide individuals with relevant and timely services, avoiding confusion or frustration due to outdated information.

Poor data quality whether personal data or not will inevitably lead to poor business decisions which will impact business operations.

Regulatory Compliance

Adhering to this principle is a vital component of GDPR compliance, minimising the risk of non-compliance penalties. There are significant reputational, financial and operational risks to a data breach so helping to avoid one is a key GDPR activity.

Greater Trust

When individuals know their data is accurate and current, they are more likely to trust organisations handling their information. This trust is essential for a transparent and respectful data processing relationship.

Any company that processes personal data cannot afford to lose the trust of customers. The same is true of employees and suppliers.

For example, if a customer’s order contains the wrong items at delivery then inaccurate data has been processed. If an employee is not paid the right amount then the company payroll has the wrong information.

Data Accuracy Throughout the Information Lifecycle

Accuracy is an ongoing responsibility that should be applied throughout the information lifecycle.

  • At Collection (Creation): Use validation tools (e.g., address lookup software, mandatory fields) at the point of data entry.
  • During Processing (Maintenance): Implement regular “data hygiene” exercises and prompt users/employees to verify their details.
  • At Disposal (End-of-Life): Ensure accuracy remains a priority until the moment of deletion. You cannot accurately fulfil a “Right to Erasure” request if your datasets are not consistent or have not been updated.

What Does “Where Necessary” Mean?

GDPR compliance is proportionate, and not every record requires continuous review or updates. The need to review information depends on:

  • the purpose of processing
  • how frequently information changes
  • the consequences of inaccuracies and the sensitivity of the data
  • the decisions being made

For example:

Payroll

Employee bank details and addresses should be kept current and confirmed from time to time to ensure people are paid on time.

Historical Investigation Records

A factual record of what was known at the time may remain accurate even if circumstances later change.

Accuracy should always be considered in the context of the purpose for which the data are processed.

Data Accuracy in Practice

Recruitment

Applicants should be given opportunities to update application information where appropriate.

Healthcare

Clinical records should accurately reflect diagnoses, treatment and professional opinions while clearly distinguishing between facts and opinions.

Human Resources

Employee records should be updated following changes to contact details, emergency contacts, job titles or contractual arrangements.

Customer Services

Contact information should be reviewed periodically to reduce failed communications.

Financial Services

Incorrect account information could lead to significant financial consequences, making regular verification particularly important.

Data Accuracy and Other GDPR Principles

The principle of data accuracy supports and it supported by the other privacy principles.

Lawfulness, Fairness and Transparency

Fair decisions depend on reliable information. Data processing may not be lawful if the data on which it is based is inaccurate. For example, the legitimate interests lawful basis relies on an assessment that depends on accurate and up to date information.

  • understand the first data privacy principle with this article

Purpose Limitation

The purpose determines how accurate information needs to be. If the purpose relies on very fresh or up to date information then mechanisms should be put in place to ensure the data remains accurate.

Data Minimisation

Maintaining unnecessary information increases the likelihood of inaccuracies. Collecting only necessary data makes it easier to verify and keep up to date.

Storage Limitation

Once data is out of date, and if it cannot be easily updated, it is likely that is can be deleted. When data has been updated normally only the most up to date version should be stored.

Accountability

Organisations should be able to demonstrate how they maintain data quality. Having proportionate systems to ensure accuracy helps to demonstrate compliance.

  • read more about the principle of accountability here.

Data Accuracy and People’s Data Rights

The GDPR gives people a number of data rights that directly link to data accuracy.

Right to Rectification

Individuals may request the correction of inaccurate personal data. This can be refused if you can demonstrate the data is accurate.

Right of Access

Subject Access Requests provide an opportunity for individuals to identify inaccuracies in their personal data.

Right to Restrict Processing

Individuals may request restrictions while disputes about accuracy are resolved.

Common Mistakes and Misconceptions

“We Collected It Correctly, So It Must Still Be Accurate”

Information can become outdated over time. The key thing is to ensure the data remains accurate at the point of processing, not just the point of collection.

“Every Record Must Be Updated Constantly”

Accuracy should be proportionate. Some records will need to be reviewed for accuracy more frequently than others.

“Opinions Cannot Be Wrong”

Opinions should be clearly distinguished from factual information and based on accurate evidence where appropriate. To comply with the principle opinions must be recorded accurately, even if they cannot be verified.

“Only Individuals Are Responsible for Updating Their Information”

Organisations also have responsibilities to maintain data quality. At a minimum organisations should clearly tell people to get in touch if their data changes.

Demonstrating Compliance

Organisations must be able to demonstrate compliance with the principle of data accuracy, and therefore be able to show how they ensure the personal data they hold is correct, complete and up to date.

Useful Evidence

  • data quality procedures
  • validation checks
  • periodic record reviews
  • audit trails
  • correction logs
  • staff training
  • Records of Processing Activities (ROPAs)
  • subject access and rectification procedures

Practical Data Accuracy Checklist

Before relying on personal data, ask:

  • Is the information accurate?
  • Is it still current?
  • Does it remain relevant to the purpose?
  • Has it been verified where appropriate?
  • Could inaccurate information affect decisions?
  • Do individuals know how to request corrections?
  • Can we demonstrate our review process?

Conclusion

Accurate personal data support fair decisions, effective services and public trust. This is why the GDPR requires organisations to take reasonable steps to maintain data quality and correct inaccuracies without undue delay.

The level of accuracy required should always reflect the purpose for which information is being processed. Therefore organisations that embed good, proportionate data quality practices into everyday operations strengthen compliance, improve governance and reduce organisational risk.