Contextual Integrity
Contextual Integrity is a theory of privacy, developed by Helen Nissenbaum, that defines privacy as the appropriate flow of information rather than as secrecy or as control over personal information. The core idea is that information shared in one social context (for example, with a doctor) carries expectations about how it should flow, and privacy is violated when information moves in ways that breach those context-specific norms. It provides a way to reason about whether a given use or sharing of information is appropriate given the setting in which it was gathered.
Contextual Integrity (CI) is a normative theory of privacy attributed to Helen Nissenbaum that frames privacy as the preservation of context-relative informational norms, i.e., appropriate information flow, rather than as data secrecy or as individual control over personal information. It evaluates information flows in terms of context-specific parameters (such as the actors involved, the type of information, and the conditions or principles under which it is transmitted), treating a privacy violation as a breach of the flow norms governing the originating context. CI is primarily an academic and conceptual model used in privacy research and, more recently, in efforts to operationalize privacy judgments in systems; it is not a statutory regime and does not itself establish legal obligations, lawful bases, roles such as controller or processor, cross-border transfer mechanics, or enforcement provisions, which are governed separately by instruments such as the EU GDPR, UK GDPR, or CCPA/CPRA. It may inform how such obligations are interpreted or designed but should not be treated as a substitute for jurisdiction-specific compliance analysis.
Why it matters
Contextual Integrity matters because it reframes what a privacy harm actually is. Many operational privacy programs default to two intuitions: privacy as secrecy (keep data hidden) or privacy as control (give individuals switches and consent boxes). Contextual Integrity argues that neither fully captures the problem. Information shared appropriately in one setting, such as with a physician, carries expectations about how it will subsequently flow. A violation can occur even when data is not made public and even when a consent mechanism was technically present, if the flow breaches the norms of the context in which the information was originally gathered. For practitioners, this offers a diagnostic lens for cases where a use feels wrong despite being nominally permitted.
The theory, developed by Helen Nissenbaum in her work on technology, policy, and the integrity of social life, has become a prominent academic account of privacy and is increasingly cited in privacy research and in efforts to operationalize privacy judgments in systems. Its practical value is analytical rather than regulatory: it helps teams articulate why a particular data flow may erode trust or defeat user expectations, which can inform design decisions, impact assessments, and policy interpretation.
It is important to be clear about scope. Contextual Integrity is a normative and conceptual model, not a statutory regime. It does not by itself create legal obligations, define roles such as controller or processor, establish lawful bases, govern cross-border transfers, or set enforcement provisions; those remain the domain of instruments such as the EU GDPR, UK GDPR, or CCPA/CPRA. Treating a Contextual Integrity analysis as a substitute for jurisdiction-specific compliance work would be a mistake. Used correctly, it complements legal analysis by clarifying the underlying expectations that regulation attempts to protect.
Who it's relevant to
Inside CI
Common questions
Answers to the questions practitioners most commonly ask about CI.