Integrity and Confidentiality

Integrity and confidentiality are at the core of the the sixth data protection principle. In this article, we will embark on a journey to explore this principle in depth, comprehending its implications, and understanding how it shapes the landscape of data management.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Contents

What Does the GDPR Say?

Article 5(f) of the GDPR says that data shall be:

“processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).

The Essence of Integrity and Confidentiality

The sixth data protection principle, often referred to as the “integrity and confidentiality” principle, is rooted in the GDPR. Its core aim is to guarantee the security and responsible handling of personal data. To unravel its significance, let’s break it down:

Deciphering Integrity

At its core, the principle of integrity ensures that personal data remains accurate and reliable. This entails taking measures to prevent unauthorised alterations, data corruption, and inaccuracies.

Accuracy and reliability are different from security, although the right security arrangements help. Remember, a data breach includes the accidental or deliberate alteration or corruption of personal data.

Safeguarding Confidentiality

Confidentiality is a cornerstone of data protection. This aspect of the principle ensures that personal data is accessible only by authorised individuals and protected from unauthorised disclosure.

Again, this goes further than security. Confidentiality can be breached by inappropriate internal data sharing or even people discussing personal information where they can be overheard.

Appropriate Security Arrangements

Information security means putting in place the right arrangements to prevent a personal data breach. As noted above this means preventing:

  • unauthorised access

  • inappropriate sharing

  • deletion or destruction

  • corruption or alteration

of data. How you prevent that depends on both the nature of the personal information that you have, and the resources available for information security. The greater the volume of personal information, the more sensitive information you have, or the vulnerabilities of the people whose information you collect or process will all influence the level of security required.

For both physical and electronic data there need to be appropriate access controls and barriers to data loss. You systems and devices should be able to record access by users and detect confidentiality breaches.

Overall the arrangements you put in place must be able to mitigate the risk of both a data breach and the consequences for people whose data are affected.

Technical and Organisational Measures

Technical and organisational measures is an important phrase. It means the GDPR expects you to go beyond physical and electronic security and think about people and organisational culture. You need the right kind of security policies, employee training, and other measures in place to help people do the right thing. You also need to ensure responsibility for information integrity and confidentiality is assigned to the right people including a Data Protection Officer.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

The Benefits of Ensuring Integrity and Confidentiality

Understanding why the integrity and confidentiality principle is pivotal is integral to responsible data management. Every business will benefit from understanding and abiding by the sixth data protection principle.

Trust and Confidence

Data integrity is inseparable from trust. When personal data is maintained with integrity, it enhances trust in data-driven processes, decisions, and the organisations that use this data. This partly comes from the need to engage with people about their data to ensure it remains accurate and up to date, and is only used for specified purposes.

Reducing the Risk of a Data Breach

Ensuring confidentiality is a crucial measure in mitigating data breach risks. By protecting data from unauthorised access, corruption or loss of data organisations reduce the probability of data breaches, safeguarding the privacy of individuals. This also reduces the risk of regulatory action, civil action, and negative publicity.

Summary: Your Obligations

The GDPR imposes specific obligations on data controllers and processors regarding the application of the integrity and confidentiality principle. They include:

Security Measures

Implementing robust security measures is non-negotiable. Encryption, access controls, and cybersecurity practices are crucial to maintaining data integrity and confidentiality.

Employee Training

Educating employees about data security and confidentiality is vital. A well-informed workforce is the first line of defense against data breaches. They will help prevent a data breach, but also help notify you quickly if anything goes wrong.

Understanding your Data Processing Activities

You cannot know what appropriate technical and organisational measures looks like for your organisation if you do not understand what personal information you need to collect and process for your business activities.

Data Security Best Practices

To uphold the principles of integrity and confidentiality, organisations must adopt best practices:

Regular Audits and Assessments

Frequent data security audits and assessments help identify vulnerabilities and maintain data integrity and confidentiality. For example each year NHS organisations undertake a diagnostic assessment called the Data Security and Protection Toolkit that looks at everything from information security to training completion.

Incident Response Plan

Being prepared for data breaches is as crucial as preventing them. An incident response plan ensures swift and effective action if a breach occurs. Protection personal data and mitigating a personal data breach should be part of every organisation’s business continuity planning.

Ethical Data Handling

Instilling a culture of ethical data handling within an organisation ensures that employees at all levels are committed to maintaining the integrity and confidentiality of personal data.

Further Reading

Explore some of the wider concepts we have touched on in this article:

  • Gain an understanding of sensitive personal data here

  • Learn more about how to handle a data breach here

  • Find out about the penalties for breaching GDPR here

Conclusion: Emphasising the Significance of Integrity and Confidentiality

The sixth data protection principle, which emphasises integrity and confidentiality, plays an indispensable role in the GDPR’s framework. Upholding this principle is not only a legal requirement but a moral obligation to safeguard data accuracy, mitigate data breach risks, and maintain individuals’ trust in data processing. By adhering to security measures, educating employees, and adopting best practices, organisations can ensure that personal data remains secure, reliable, and confidential, thereby promoting responsible data management and protecting individuals’ rights.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial