> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What Does “Integrity and Confidentiality” Mean Under the GDPR?
- URL: https://www.thedelatorrereview.com/what-does-integrity-and-confidentiality-mean-under-the-gdpr/
- Published: 2019-01-22T13:34:00.000Z
- Updated: 2026-07-11T14:04:16.000Z
- Description: The GDPR’s integrity and confidentiality principle requires organizations to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. Learn the risk-based security obligations and the technical and organizational measures required for compliance effectively.
- Author: Lydia
- Tags: Integrity and Confidentiality, Security, GDPR, Principles, EU, Data Protection Law, Pseudonymization, Encryption, Privacy by Design

### 

There are seven basic data protection principles under EU data protection law. The sixth principle is the principle of “integrity and confidentiality” (GDPR Article 5 (1) (f)).

---

> Article 5 of GDPR

(1)Personal data shall be:

(f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).

\[See also Articles 24 and 32 of GDPR\]

---

Controllers and processors **must ensure that appropriate security measures** are in place to prevent data from being accidentally or deliberately compromised.

This principle is closely related to information security which includes cybersecurity (the protection of your networks and information systems from attack), and other things like physical and organizational security measures.

Article 32 of the GDPR provides more specifics on the security of your processing.

> Article 32(1): ‘Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk’

## Why does integrity and confidentiality matter?

The principle of **integrity and confidentiality** is intended to protect individuals from the risks that arise when personal data is lost, altered, disclosed, or accessed without authorization. Poor information security can expose individuals to significant harm and may undermine public trust in organizations that process personal data.

Examples of harm resulting from inadequate security include:

- identity theft and identity fraud;
- financial fraud and unauthorized transactions;
- phishing and other social engineering attacks made more convincing through compromised personal data;
- unauthorized disclosure of sensitive personal information;
- reputational damage, embarrassment, or discrimination;
- exposure of individuals at risk, such as victims of domestic violence, witnesses, law enforcement personnel, or other vulnerable persons;
- unauthorized profiling or misuse of personal data; and
- loss of confidentiality affecting trade secrets or other sensitive business information.

Although serious harm does not occur in every case, the GDPR recognizes that individuals are entitled to protection from **any unauthorized processing** of their personal data, including processing that results only in inconvenience, anxiety, or loss of control over their information.

Strong security measures are therefore not only a legal requirement under Articles 5(1)(f) and 32 of the GDPR, but also a cornerstone of good data governance. Effective security supports compliance with other GDPR obligations, including accountability, data minimization, storage limitation, and the rights of data subjects. It also demonstrates that an organization has implemented appropriate technical and organizational measures consistent with a risk-based approach.

## What must security measures protect?

The integrity and confidentiality principle extends far beyond cybersecurity or protecting data from external hackers. It applies **throughout the entire lifecycle of personal data**, regardless of whether the information is stored electronically or on paper.

Security measures should ensure that:

- personal data is accessed, used, modified, disclosed, or deleted only by persons authorized to do so;
- personal data remains accurate, complete, and protected against unauthorized alteration;
- personal data remains available and recoverable when needed, including after accidental loss, destruction, or technical failure; and
- organizations can restore the availability and integrity of personal data in a timely manner following an incident.

These objectives correspond to the three fundamental pillars of information security:

- **Confidentiality** – preventing unauthorized access or disclosure.
- **Integrity** – ensuring that data remains accurate, complete, and protected against unauthorized modification.
- **Availability** – ensuring that authorized users can access personal data whenever it is required.

Together, these concepts form the foundation of the GDPR's security obligations.

## What level of security does the GDPR require?

The GDPR deliberately avoids prescribing a fixed list of security controls. Instead, Article 32 requires controllers and processors to implement **technical and organizational measures appropriate to the risk** presented by the processing.

Determining what is "appropriate" requires consideration of factors such as:

- the state of the art;
- the costs of implementation;
- the nature, scope, context, and purposes of the processing;
- the likelihood and severity of the risks to individuals' rights and freedoms; and
- the characteristics of the personal data being processed, including whether special categories of personal data are involved.

This reflects the GDPR's **risk-based approach**. Appropriate security measures will differ depending on the organization, the processing activities, and the potential impact on individuals. There is no universal checklist that applies equally to every controller or processor.

Before selecting security measures, organizations should conduct a risk assessment that considers, among other things:

- the sensitivity and volume of the personal data processed;
- the potential harm to individuals if the data were compromised;
- the organization's physical and technological infrastructure;
- the number of personnel with access to the data and the effectiveness of access controls;
- the use of processors or other third parties; and
- the likelihood of accidental or malicious incidents.

The outcome of this assessment should guide the selection of appropriate technical and organizational measures, ensuring that security remains proportionate to the risks throughout the lifecycle of the processing.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-11--2026-at-06_52_24-AM.png)

### ICO Checklist

The [Information Commissioner’s Office](https://ico.org.uk/?ref=thedelatorrereview.com) website includes a helpful Checklist that summarizes this principle:

![](https://cdn-images-1.medium.com/max/800/0*ZO9tJcRUmrqfN1Mr)

### Consequences of non-compliance

Failure to comply with data protection principles may lead to substantial fines. Article 83(5)(a) of GDPR states that infringements of the basic principles for processing personal data are subject to the highest tier of administrative fines. This could mean a fine of up to €20 million, or 4% of your total worldwide annual turnover, whichever is higher.

### Resources

ICO - [A Guide to Information Security](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/?ref=thedelatorrereview.com)

Related recitals: [(75) Risks to the Rights and Freedoms of Natural Persons](https://gdpr-info.eu/recitals/no-75/?ref=thedelatorrereview.com) [(76) Risk Assessment](https://gdpr-info.eu/recitals/no-76/?ref=thedelatorrereview.com) [(77) Risk Assessment Guidelines](https://gdpr-info.eu/recitals/no-77/?ref=thedelatorrereview.com) [(78) Appropriate Technical and Organisational Measures](https://gdpr-info.eu/recitals/no-78/?ref=thedelatorrereview.com) [(79) Allocation of the Responsibilities](https://gdpr-info.eu/recitals/no-79/?ref=thedelatorrereview.com) [(83) Security of Processing](https://gdpr-info.eu/recitals/no-83/?ref=thedelatorrereview.com)

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/Screenshot-2026-07-04-at-4.45.19---PM-43.png)