Skip to main content
Category: Privacy Principles

Integrity and Confidentiality

Also known as: Security Principle, Principle (f), Integrity and Confidentiality (Security)
Simply put

Integrity and confidentiality is the data protection principle requiring organisations to keep personal data secure, protecting it against unauthorised access, loss, or damage. In plain terms, it means having appropriate measures in place so that personal data stays accurate, is not tampered with, and is only seen by people who are allowed to see it. This principle concerns the security of personal data; it does not on its own cover other obligations such as retention periods or how long data may be kept.

Formal definition

Under the UK GDPR, integrity and confidentiality is one of the data protection principles, often described as the 'security' principle, requiring that personal data be processed using appropriate technical and organisational measures to ensure its security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage. In this context, confidentiality generally means preserving authorised restrictions on access and disclosure, while integrity generally means ensuring that information is not altered in an unauthorised or accidental manner. This principle sits at the overlap of data governance and information security: it establishes a governance-level obligation on the controller (and, where relevant, imposes corresponding security duties on processors) while drawing on established security concepts such as confidentiality and integrity, which also appear within the broader CIA triad (confidentiality, integrity, availability) in information security practice. The appropriateness of measures is context-dependent and risk-based; no single control guarantees compliance, and demonstrable evidence of implemented measures is generally required rather than stated intent. This entry defines the principle itself and does not address cross-border transfer mechanics, retention rules, breach notification timelines, or enforcement penalties, and equivalent security requirements under other regimes such as the EU GDPR, HIPAA, or the CCPA/CPRA may be framed or scoped differently.

Why it matters

Integrity and confidentiality is the principle that most directly connects data protection law to day-to-day security operations. If personal data can be read by people who should not see it, or altered without authorisation, the individuals whose data is affected face real harms, and the controller has failed a core obligation. Because this principle is expressed as a governance-level duty on the controller, a security failure is not treated purely as a technical incident; it is a compliance matter that requires the organisation to show it had appropriate measures in place, not merely that it intended to protect the data.

The principle is framed in a risk-based way, which is precisely why it is demanding in practice. There is no fixed checklist that, once completed, guarantees compliance; the appropriateness of technical and organisational measures depends on the nature of the data, the processing, and the risks involved. This means organisations must be able to justify their choices and produce demonstrable evidence of what they implemented and why. Two organisations handling different categories of personal data may reasonably arrive at different security postures, and both may be defensible provided each can evidence a proportionate, considered approach.

This entry addresses only the security principle itself. It does not cover breach notification timelines, retention rules, cross-border transfer mechanics, or enforcement penalties, and it does not describe how the equivalent security requirements are framed under other regimes. A weakness in integrity or confidentiality often surfaces alongside those other obligations, but they are distinct duties and should be assessed separately.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy leads need to treat this principle as a governance obligation on the controller, not solely a technical problem for the security team. They should focus on whether the organisation can demonstrate that its measures are appropriate and proportionate to the risk, since stated intent is generally not enough and evidence of implementation is expected.
Information security professionals
Security teams operationalise this principle through the technical controls that preserve confidentiality (authorised restrictions on access and disclosure) and integrity (protection against unauthorised or accidental alteration). It is useful to recognise the alignment with the CIA triad while remembering that the legal principle is scoped to personal data and framed as a risk-based standard rather than a fixed control set.
Data governance and stewardship functions
Governance functions own the policy, ownership, and accountability layer that sits above individual controls. Their role is to ensure that the organisation's approach to securing personal data is documented, justified, and evidenced, reflecting that this principle draws on both data governance and information security without collapsing the two.
Compliance and legal teams
Compliance and legal professionals must be able to defend the organisation's security posture as appropriate given the specific data and risks involved, without assuming any single measure guarantees compliance. They should also keep this principle distinct from separate obligations such as retention, breach notification, and cross-border transfers, which this principle does not itself govern.
Processors and their engagement owners
Where an organisation acts as a processor, corresponding security duties apply, and those managing processor relationships on the controller side should ensure that appropriate measures and evidence of them are addressed. This helps ensure the controller can demonstrate that security obligations extend across the processing chain.

Inside Integrity and Confidentiality

Confidentiality
The principle that personal data is protected against unauthorized or unlawful access and disclosure. It is one of the two limbs of the integrity and confidentiality principle articulated in the EU GDPR and mirrored in the UK GDPR, and it aligns with the confidentiality objective familiar from information security practice.
Integrity
The requirement that personal data is protected against unauthorized or unlawful alteration, and against accidental damage or corruption. This limb overlaps with the integrity objective in information security, though here it is framed as a data protection obligation rather than a purely technical control.
Appropriate security measures
The principle calls for appropriate technical and organizational measures rather than a fixed checklist. What is appropriate is context-dependent, generally assessed against factors such as the nature of the data, the risks to individuals, and the state of the art. No single control satisfies this obligation on its own.
Technical and organizational measures
Security under this principle is not limited to technology. It typically combines technical controls (for example access controls and encryption where suitable) with organizational measures (for example policies, staff training, and defined responsibilities). Both categories generally need evidence to demonstrate accountability.
Relationship to accountability
The integrity and confidentiality principle interacts with the separate accountability principle, under which a controller must be able to demonstrate compliance. Stating that security measures exist is generally insufficient; demonstrable evidence of their implementation and ongoing operation is typically expected.

Common questions

Answers to the questions practitioners most commonly ask about Integrity and Confidentiality.

Does encrypting personal data mean it is no longer personal data and therefore outside the scope of the integrity and confidentiality principle?
No. Encryption is a security measure that supports the integrity and confidentiality principle, but it does not convert personal data into non-personal data. As long as the data can be re-identified by anyone holding the key or by other reasonably likely means, it generally remains personal data and stays within scope. Encryption and tokenization are risk-reducing controls, not a route out of the applicable obligations.
Is the integrity and confidentiality principle just another way of describing information security controls?
Not quite. Information security is concerned with confidentiality, integrity, and availability of information generally, while the integrity and confidentiality principle typically frames the security of processing as an obligation attached to personal data specifically. The two overlap substantially in the controls they rely on, but the principle sits within a data protection accountability context and does not replace or fully map to a broader information security programme. Treating them as identical risks missing governance obligations that fall outside a purely security remit.
What types of controls are generally used to satisfy this principle in practice?
Organisations typically combine technical and organisational measures. Technical measures often include access controls, encryption, pseudonymisation, logging and monitoring, and integrity checks. Organisational measures often include role-based access policies, staff training, and defined responsibilities. The appropriate mix generally depends on the risk to individuals, the nature of the data, and the state of the art, so there is no single prescribed control set that applies universally.
How should the appropriate level of security be determined for a given processing activity?
The level is generally assessed by reference to the risk that the processing poses to individuals, taking into account factors such as the nature, scope, and purpose of the processing and the sensitivity of the data involved. Higher-risk or special category processing typically warrants stronger measures. Because the standard is risk-based rather than fixed, the determination should be documented so that the reasoning can be demonstrated later.
What evidence demonstrates compliance with the integrity and confidentiality principle?
Under accountability-oriented frameworks, stated intent is generally insufficient; demonstrable evidence is expected. This can include documented security policies, records of the controls implemented, results of testing or assessment, access and change logs, and evidence of periodic review. The goal is to be able to show, not merely assert, that appropriate measures were selected and maintained relative to the assessed risk.
How does this principle relate to handling a personal data breach?
The integrity and confidentiality principle concerns preventing unauthorised or unlawful processing and accidental loss, destruction, or damage, so a breach may indicate that the applicable measures were inadequate. This entry addresses the security-of-processing obligation itself and does not cover breach notification timelines, thresholds, or the mechanics of who must be informed, which are governed by separate provisions that vary by jurisdiction.

Common misconceptions

Encrypting or tokenizing personal data makes it non-personal and removes it from scope.
Encryption and tokenization are security measures that can help satisfy the integrity and confidentiality principle, but they generally do not render data non-personal. Because such transformations are typically reversible by parties holding the relevant keys or mappings, the underlying data usually remains personal data and remains in scope.
This principle is purely an information security obligation that belongs solely to the security team.
While the integrity and confidentiality principle overlaps substantially with information security's confidentiality and integrity objectives, it is a data protection principle that sits alongside governance responsibilities. Accountability for it generally rests with the controller, and organizational measures such as policy and training are part of the obligation, not only technical controls.
Implementing a specific control, such as encryption, guarantees compliance with this principle.
No single control guarantees compliance. The principle requires measures that are appropriate to the context and risk, and adequacy is assessed against the circumstances of the processing. Compliance depends on implementation, jurisdiction, and the ability to demonstrate that the chosen measures are appropriate and operating.

Best practices

Select technical and organizational measures based on a documented assessment of the data involved and the risks to individuals, rather than adopting a fixed control checklist and assuming it is sufficient.
Treat encryption, tokenization, and similar techniques as security measures that support this principle, while continuing to manage the underlying data as personal data because such transformations are generally reversible.
Combine technical controls with organizational measures such as policies, defined responsibilities, and staff training, since the principle addresses both categories.
Retain demonstrable evidence that measures are implemented and operating, so the controller can satisfy the related accountability expectation rather than relying on stated intent.
Review the appropriateness of measures periodically and after material changes to processing, recognizing that what counts as appropriate is context-dependent and can shift over time.
Coordinate between information security and data protection functions so that confidentiality and integrity objectives are addressed as a shared responsibility without collapsing governance accountability into a purely technical task.