TY - JOUR T1 - All Talk, No Action? The Effect of the GDPR Accountability Principle on the EU Data Protection Paradigm A1 - Karjalainen, Tuulia PY - 2022 N2 - The General Data Protection Regulation (679/2016, ’GDPR’) introduced the accountability principle to the field of EU data protection law. The principle aims to increase the controller’s responsibility for its personal data processing and to promote a risk-based approach to data protection. However, accountability, as implemented in the GDPR, fails to meet these objectives. Accountability is sometimes seen as a significant paradigm shift – as a move away from transparency and choice-based data subject control towards company liability. However, the principle does not truly replace the requirements-based approach in the GDPR. Nevertheless, accountability can effectively contribute to EU data protection law by reinforcing other GDPR obligations. This article analyses the contribution of the GDPR accountability principle to the EU data protection law, and the effectiveness of the principle in the light of its objectives. Although accountability does not radically change the European data protection paradigm, the principle does contribute to increasing controllers’ responsibility and facilitating enforcement. keywords: Accountability | GDPR | Article 5(2) | Risk-based Approach | Big Data JF - European Data Protection Law Review JA - European Data Protection Law Review VL - 8 IS - 1 UR - https://doi.org/10.21552/edpl/2022/1/6 M3 - doi:10.21552/edpl/2022/1/6 ER -