Every organisation that processes personal data has a responsibility to protect it. Whether information is stored electronically, on paper or shared verbally, individuals expect it to remain accurate, available when needed and protected against unauthorised access, loss or misuse. The GDPR's integrity and confidentiality principle establishes the security and governance