Integrity and Confidentiality
Integrity and confidentiality is the data protection principle requiring organisations to keep personal data secure, protecting it against unauthorised access, loss, or damage. In plain terms, it means having appropriate measures in place so that personal data stays accurate, is not tampered with, and is only seen by people who are allowed to see it. This principle concerns the security of personal data; it does not on its own cover other obligations such as retention periods or how long data may be kept.
Under the UK GDPR, integrity and confidentiality is one of the data protection principles, often described as the 'security' principle, requiring that personal data be processed using appropriate technical and organisational measures to ensure its security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage. In this context, confidentiality generally means preserving authorised restrictions on access and disclosure, while integrity generally means ensuring that information is not altered in an unauthorised or accidental manner. This principle sits at the overlap of data governance and information security: it establishes a governance-level obligation on the controller (and, where relevant, imposes corresponding security duties on processors) while drawing on established security concepts such as confidentiality and integrity, which also appear within the broader CIA triad (confidentiality, integrity, availability) in information security practice. The appropriateness of measures is context-dependent and risk-based; no single control guarantees compliance, and demonstrable evidence of implemented measures is generally required rather than stated intent. This entry defines the principle itself and does not address cross-border transfer mechanics, retention rules, breach notification timelines, or enforcement penalties, and equivalent security requirements under other regimes such as the EU GDPR, HIPAA, or the CCPA/CPRA may be framed or scoped differently.
Why it matters
Integrity and confidentiality is the principle that most directly connects data protection law to day-to-day security operations. If personal data can be read by people who should not see it, or altered without authorisation, the individuals whose data is affected face real harms, and the controller has failed a core obligation. Because this principle is expressed as a governance-level duty on the controller, a security failure is not treated purely as a technical incident; it is a compliance matter that requires the organisation to show it had appropriate measures in place, not merely that it intended to protect the data.
The principle is framed in a risk-based way, which is precisely why it is demanding in practice. There is no fixed checklist that, once completed, guarantees compliance; the appropriateness of technical and organisational measures depends on the nature of the data, the processing, and the risks involved. This means organisations must be able to justify their choices and produce demonstrable evidence of what they implemented and why. Two organisations handling different categories of personal data may reasonably arrive at different security postures, and both may be defensible provided each can evidence a proportionate, considered approach.
This entry addresses only the security principle itself. It does not cover breach notification timelines, retention rules, cross-border transfer mechanics, or enforcement penalties, and it does not describe how the equivalent security requirements are framed under other regimes. A weakness in integrity or confidentiality often surfaces alongside those other obligations, but they are distinct duties and should be assessed separately.
Who it's relevant to
Inside Integrity and Confidentiality
Common questions
Answers to the questions practitioners most commonly ask about Integrity and Confidentiality.