← All GDPR articles

Art.5

Principles relating to processing of personal data

The foundational principles — data minimization, purpose limitation, accuracy, and integrity — that govern all lawful personal-data processing.

Why it matters for SaaS exits

Buyers use Art.5 as the umbrella test: if a SaaS hasn't even mapped what data it collects and why, every downstream article is suspect. A seller who can't explain their data minimization rationale gets a valuation haircut because the buyer inherits unknown processing risk.

What we scan for

We check whether the site's privacy policy discloses data collection purposes (purpose limitation) and whether cookie categories are labeled with their function (minimization signal). Sites that set cookies without any documented purpose fail this check.

Automated checks (0)

No automated checks map to this article yet.

Buyer due-diligence checklist

  • Ask the seller for a data inventory (ROPA) — what data, why, where stored.
  • Check if the privacy policy lists specific processing purposes, not just legal boilerplate.
  • Verify cookie categories are documented (necessary/functional/analytics/marketing).

Run this scan on your site

See exactly where your site stands on Art.5 before a buyer asks.

Scan free →