Every organisation that processes personal data has a responsibility to protect it. Whether information is stored electronically, on paper or shared verbally, individuals expect it to remain accurate, available when needed and protected against unauthorised access, loss or misuse. The GDPR’s integrity and confidentiality principle establishes the security and governance arrangements needed to achieve this.
What Does the GDPR Say?
Article 5(f) of the GDPR says that data shall be:
“processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).”
Why Integrity and Confidentiality Matters
Poor information security can result in:
- identity theft
- financial loss
- discrimination
- reputational damage
- operational disruption
- regulatory action
This core GDPR principles was created to ensure organisations manage these risks and avoid data breaches.
Understanding Integrity
In the context of “Integrity and Confidentiality” integrity refers to ensuring that personal data remains accurate, complete, and untampered with throughout its entire lifecycle.
While “confidentiality” focuses on preventing unauthorised access integrity focuses on preventing unauthorised alteration or loss (keeping data reliable).
The Three Elements of Integrity
- Protection Against Unauthorised Alteration: Data must be protected from intentional or accidental changes by unauthorised parties. This means if a hacker breaches a system, they should not be able to modify the data (e.g., changing a bank account number or altering a performance review).
- Completeness and Accuracy: Integrity ensures that the data remains in its intended state. If a system failure or a human error causes part of a record to be corrupted or deleted, the integrity of that data has been compromised.
- Reliability and Trustworthiness: Integrity ensures that when an organisation retrieves data, it can be confident that the data is exactly as it was when it was first collected or last updated. If you cannot guarantee integrity, the data becomes useless, and any decision made based on it is flawed.
How Integrity is Practically Achieved
To satisfy this principle, organizations use technical and organizational measures such as:
- Access Controls: Restricting who has “write” or “edit” permissions to sensitive datasets ensures that only authorised people can change information.
- Audit Trails: Maintaining logs that record who changed what and when. This makes it possible to detect unauthorized tampering and revert changes if integrity is compromised.
- Data Backups: Regularly backing up data protects against loss or corruption due to technical failures, ensuring that a “golden copy” remains available.
Safeguarding Confidentiality
Confidentiality is a cornerstone of data protection. This aspect of the principle ensures that personal data is accessible only by authorised individuals and protected from unauthorised disclosure.
Again, this goes further than security. Confidentiality can be breached by inappropriate internal data sharing or even people discussing personal information where they can be overheard.
Examples of confidentiality failures:
- emailing the wrong recipient
- discussing cases in public
- excessive staff access
- unsecured filing cabinets
- unlocked laptops
- weak passwords
- oversharing internally
Confidentiality is about people and processes as much as cyber security.
Appropriate Security Arrangements
Information security means putting in place the right arrangements to prevent a personal data breach. As noted above this means preventing:
- unauthorised access
- inappropriate sharing
- deletion or destruction
- corruption or alteration
of data. How you prevent that depends on both the nature of the personal information that you have, and the resources available for information security. The greater the volume of personal information, the more sensitive information you have, or the vulnerabilities of the people whose information you collect or process will all influence the level of security required.
For both physical and electronic data there need to be appropriate access controls and barriers to data loss. You systems and devices should be able to record access by users and detect confidentiality breaches.
Overall the arrangements you put in place must be able to mitigate the risk of both a data breach and the consequences for people whose data are affected. Remember, security should be proportionate.
Factors that affect the level of security needed include:
- sensitivity
- volume
- vulnerability
- likelihood
- consequences
- available technology
- implementation costs
Technical and Organisational Measures
Technical and organisational measures is an important phrase. It means the GDPR expects you to go beyond physical and electronic security and think about people and organisational culture. You need the right kind of security policies, employee training, and other measures in place to help people do the right thing. You also need to ensure responsibility for information integrity and confidentiality is assigned to the right people including a Data Protection Officer.
Technical Measures
Technical measures include:
- encryption
- MFA
- firewalls
- backups
- monitoring
- access controls
- logging
Organisational Measures
Organisational, or people focussed, measures include:
- policies
- staff training
- contracts
- governance
- DPIAs
- supplier management
- incident reporting
- straightforward systems for information classification
Examples
HR
Restrict access to both paper and electronic employee records.
Healthcare
Role-based access to patient record systems.
Finance
Encrypting payment data at rest and in transit.
Remote Working
VPNs and secure devices to ensure there are no additional security risks from working at home.
Verifying recipients before sending email.
Learn More About the GDPR
Develop the skills you need to understand, apply and comply with the GDPR with this five-star rated training course. Available in person, online and in house, this expert-led learning is perfect for anyone who needs practical skills in the management of personal data.

The Benefits of Ensuring Integrity and Confidentiality
Integrity and confidentiality is essential for the responsible management of personal data. Every business will benefit from understanding and abiding by the sixth data protection principle.
Trust and Confidence
Data integrity is inseparable from trust. When personal data is maintained with integrity, it enhances trust in data-driven processes, decisions, and the organisations that use this data. This partly comes from the need to engage with people about their data to ensure it remains accurate and up to date, and is only used for specified purposes.
Reducing the Risk of a Data Breach
Ensuring confidentiality is a crucial measure in mitigating data breach risks. By protecting data from unauthorised access, corruption or loss of data organisations reduce the probability of data breaches, safeguarding the privacy of individuals. This also reduces the risk of regulatory action, civil action, and negative publicity.
Summary: Your Obligations
The GDPR imposes specific obligations on data controllers and processors regarding the application of the integrity and confidentiality principle. They include:
Security Measures
Implementing robust security measures is non-negotiable. Encryption, access controls, and cybersecurity practices are crucial to maintaining data integrity and confidentiality.
Employee Training
Educating employees about data security and confidentiality is vital. A well-informed workforce is the first line of defense against data breaches. They will help prevent a data breach, but also help notify you quickly if anything goes wrong.
Understanding your Data Processing Activities
You cannot know what appropriate technical and organisational measures looks like for your organisation if you do not understand what personal information you need to collect and process for your business activities.
Demonstrating Compliance
To uphold the principles of integrity and confidentiality, organisations should employ a range of approaches:
Regular Audits and Assessments
Frequent data security audits and assessments help identify vulnerabilities and maintain data integrity and confidentiality. For example each year NHS organisations undertake a diagnostic assessment called the Data Security and Protection Toolkit that looks at everything from information security to training completion.
Incident Response Plan
Being prepared for data breaches is as crucial as preventing them. An incident response plan ensures swift and effective action if a breach occurs. Protection personal data and mitigating a personal data breach should be part of every organisation’s business continuity planning.
Ethical Data Handling
Instilling a culture of ethical data handling within an organisation ensures that employees at all levels are committed to maintaining the integrity and confidentiality of personal data.
Evidence of compliance includes:
Evidence includes:
- Information Security Policy
- access reviews
- penetration testing
- audit logs
- DPIAs
- DSP Toolkit
- ISO 27001
- incident logs
- training records
Conclusion
Integrity and confidentiality are about more than preventing cyber attacks. They require organisations to build appropriate technical controls, organisational measures and a culture of responsible information handling. By embedding security into everyday business processes, organisations strengthen compliance, reduce organisational risk and build confidence among customers, employees and regulators.
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: