Privacy, Security, and Data ProtectionE-Government and Public ServicesEthics and Social Impacts of AI

Anamarija Mladinić, Ljerka Luić

2026.6.14Laws

DOI: 10.3390/laws15030056

Abstract

Article 5 GDPR sets out the core principles governing the lawful processing of personal data and occupies a central place in the EU data protection framework. However, empirical evidence on how Article 5 is reflected in supervisory practice across the European Economic Area remains limited. This article addresses that gap through an empirical analysis of 790 national data protection authority decisions involving infringements related to Article 5 GDPR, drawn from an initial GDPRhub retrieval pool of 1660 publicly available decisions issued between 25 May 2018 and 15 September 2025. Using structured content analysis, the article identifies recurring infringement patterns, examines the co-occurrence of Article 5 with other GDPR provisions, and analyses selected sectoral, contextual, and outcome-related dimensions of supervisory practice. The findings show that Article 5-related infringements most frequently concern lawfulness, fairness and transparency, data minimisation, integrity and confidentiality, and accountability, and that they often appear alongside infringements of Article 6, Articles 12 to 14, and Article 32 GDPR. The analysis further points to meaningful sectoral variation, while organisation-size findings remain exploratory. Although only a limited subset of the analysed decisions was explicitly AI-related, the recurring legal weaknesses identified in the published decision record remain highly relevant for automated and data-intensive processing environments.

Citation format

MLADINIĆ, Anamarija; LUIĆ, Ljerka. Article 5 GDPR in EEA supervisory authority decisions: Enforcement patterns and co-occurring infringements. Laws, 2026, 15(3): 56.