The idea of liability to provide an account of oneself – particularly to a given authority or public – has found expression in this term since the eighteenth century. The more specific principle of accountability entered the data protection lexicon in the 1980 OECD Guidelines and has featured in numerous legislative regimes ever since.
Accountability can be seen as the overall spirit of compliance with privacy and data protection laws, as well as finding expression in some of their more concrete requirements. Examples of discrete accountability mechanisms include certification with an accountability agent (under the APEC Privacy Principles), requirements to keep adequate documentation, mandatory reporting of breaches and Data Protection Impact Assessments.
Demetzou, K., 2019. Data Protection Impact Assessment: a tool for accountability and the unclarified concept of ‘high risk’ in the General Data Protection Regulation. Computer Law and Security Review, 35(6), 105342, https://doi.org/10.1016/j.clsr.2019.105342.
European Data Protection Supervisor, 2015. Opinion 3/2015: Europe’s big opportunity. Available from: https://edps.europa.eu/sites/edp/files/publication/15-10-09_gdpr_with_addendum_en.pdf.
Guagnin, D., 2012. Managing privacy through accountability. Basingstoke: Palgrave Macmillan.
Demetzou, K., 2019. Data Protection Impact Assessment: a tool for accountability and the unclarified concept of ‘high risk’ in the General Data Protection Regulation. Computer Law and Security Review, 35(6), 105342, https://doi.org/10.1016/j.clsr.2019.105342.
European Data Protection Supervisor, 2015. Opinion 3/2015: Europe’s big opportunity. Available from: https://edps.europa.eu/sites/edp/files/publication/15-10-09_gdpr_with_addendum_en.pdf.
Guagnin, D., 2012. Managing privacy through accountability. Basingstoke: Palgrave Macmillan.