Confidentiality
Confidentiality means protecting information so that it is only accessible to people, systems, or processes that are authorized to see it. It is about preventing unauthorized access, disclosure, or theft of data, whether that data is stored, being processed, or in transit. In practical terms, it is the safeguard that keeps private or sensitive information from being exposed to those who should not have it.
Confidentiality is the assurance that information is not disclosed to unauthorized persons, processes, or devices, spanning data in storage, during processing, and (per common security framing) in transit. As one of the core information security objectives, it is achieved through access controls, authentication, and related safeguards that protect data against unintentional, unlawful, or unauthorized access, disclosure, or theft. Confidentiality is a security property and should not be equated with the broader set of data governance obligations; it addresses whether data is exposed to unauthorized parties rather than data ownership, quality, lineage, or lawful basis for processing. This entry defines the concept only and does not cover specific technical control implementations, applicable regulatory disclosure duties, breach notification requirements, or how confidentiality controls interact with the classification of data as personal or special category data.
Why it matters
Confidentiality is one of the foundational objectives of information security, and its failure is what most people mean when they refer to a data breach in everyday terms. When information is disclosed to parties who are not authorized to see it, the harm can extend from reputational damage and loss of trust to legal exposure and direct harm to the individuals whose information was exposed. In sectors that handle particularly sensitive information, such as healthcare, confidentiality has long been understood as a core professional obligation, framed as the principle of keeping information given by or about an individual secure and secret from others.
It is important to be precise about what confidentiality does and does not address. Confidentiality is a security property concerned with whether data is exposed to unauthorized persons, processes, or devices. It is not the same as the broader set of data governance obligations, which cover matters such as data ownership, quality, lineage, and the lawful basis for processing. A system can enforce strong confidentiality controls and still fall short on governance, and vice versa. Treating the two as interchangeable is a common mistake that leads organizations to overstate their compliance posture.
Because confidentiality applies to data in storage, during processing, and, under common security framing, in transit, it must be considered across the full lifecycle of information rather than at a single point. This entry defines the concept only; it does not address specific regulatory disclosure duties, breach notification requirements, or how confidentiality controls relate to whether data is classified as personal or special category data. Those determinations depend on jurisdiction and context and should be assessed separately.
Who it's relevant to
Inside Confidentiality
Common questions
Answers to the questions practitioners most commonly ask about Confidentiality.