Integrity
In a data protection and security context, integrity refers to keeping data accurate, complete, and unchanged except through authorized means. It is one of the core aims of information security, alongside confidentiality and availability. The evidence available here does not cover the technical or regulatory framing of integrity, so this entry describes the general concept rather than a specific standard's definition.
Integrity, within information security, generally denotes the property that data is protected against unauthorized or accidental alteration, ensuring it remains accurate, complete, and reliable throughout its lifecycle. It is conventionally treated as one component of the confidentiality-integrity-availability model and is distinct from data governance concerns such as data quality, lineage, and stewardship, even where those disciplines overlap in practice. The evidence packet provided does not include authoritative security or regulatory sources (for example, ISO/IEC standards, the NIST Privacy Framework, or the GDPR) defining integrity; the sources present address integrity as a moral or ethical virtue rather than as a security property. Accordingly, this entry does not cite a governing instrument, and its scope excludes specific control requirements, measurement methods, and regulatory obligations, which should be sourced from an appropriate standard or legal text.
Why it matters
In information security, integrity is one of the three core aims commonly grouped as confidentiality, integrity, and availability. Where integrity fails, data can be altered, corrupted, or falsified without detection, undermining any decision, transaction, or record that relies on it. For compliance officers and privacy engineers, this matters because personal data that cannot be trusted to be accurate and complete may lead to wrongful outcomes for data subjects and may erode the demonstrable accountability that governance frameworks generally require. Stated intent to protect data is not sufficient; the ability to show that data has been preserved against unauthorized or accidental change is what makes integrity meaningful in practice.
Integrity also sits at the boundary between information security and data governance, and conflating the two is a common expert-level error. Security-side integrity concerns protection of data against unauthorized or accidental alteration, while governance-side disciplines such as data quality, lineage, and stewardship address whether data is fit for purpose and how its origins are tracked. These overlap in practice, but they are not the same thing, and an entry that collapses them risks assigning obligations to the wrong function.
It should be noted that the evidence available for this entry does not include authoritative security or regulatory sources defining integrity as a security property. The sources present treat integrity as a moral or ethical virtue rather than a technical control objective. As a result, this discussion describes the general concept and does not draw on a specific standard or legal instrument; readers requiring control requirements, measurement methods, or regulatory obligations should consult an appropriate standard or legal text.
Who it's relevant to
Inside Integrity
Common questions
Answers to the questions practitioners most commonly ask about Integrity.