Data Protection HubIndividual TopicsPrinciples Relating to Processing

Integrity and Confidentiality (Article 5(1)(f) GDPR)

Data security as a principle of the GDPR: protection against unauthorized processing, loss and destruction; the relationship to Article 32 GDPR; the risk-based standard governing security measures.

Article 5(1)(f) GDPR elevates data security to the rank of a principle. The provision requires that personal data be processed in a manner that "ensures appropriate security of the personal data". It identifies two objectives which the measures must serve: integrity and confidentiality.

Key takeaways

  • The principle establishes data security as a self-standing principle with two protection objectives: integrity (the data remaining intact) and confidentiality (protection against unauthorized knowledge of the data).
  • It covers not only deliberate interference but also accidental loss, destruction and damage (operator error, hardware failure, natural events).
  • The standard is risk-based: what constitutes appropriate security depends on the risk and on the nature, scope and context of the processing, as well as on the significance of the data.
  • Special categories of data under Article 9(1) GDPR give rise to a heightened need for protection.
  • The principle is given concrete shape by Article 32 GDPR and interlocks with Articles 25, 28, 33, 34 and 35 GDPR; an infringement may attract an administrative fine.

1 Overview

1.1 The two protection objectives

  • Integrity denotes protection of the intactness of the data. Data must not be erased, destroyed or altered, in whole or in part, without authorization.
  • Confidentiality denotes protection against unauthorized knowledge of the data and thus against unauthorized processing by third parties.

The principle covers not only deliberate interference but expressly also accidental loss, accidental destruction and accidental damage. It therefore extends to matters such as operator error, hardware failure and natural events.

1.2 Relationship to Article 32 GDPR

The principle is given concrete shape by Article 32 GDPR. Article 32(1) GDPR obliges controllers and processors to implement appropriate technical and organizational measures ensuring a level of security appropriate to the risk. Under Article 32(1)(b) GDPR, ensuring the confidentiality, integrity, availability and resilience of the systems is among the central protection objectives.

An infringement of the principle renders the processing unlawful and may attract an administrative fine under Article 83(5)(a) GDPR; in addition, the notification obligations under Articles 33 and 34 GDPR may apply where there has been a personal data breach.

2 The standard of "appropriate" security

2.1 Risk-based approach

Whether the security measures are appropriate depends on the circumstances of the processing. The decisive factors are:

Where financial data, data concerning health or other special categories of personal data under Article 9(1) GDPR are involved, the need for protection is heightened. Correspondingly higher requirements are to be imposed on encryption, access controls and logging.

2.2 Access to data and equipment

Recital 39, twelfth sentence, GDPR requires that unauthorized persons obtain neither "access to or use of personal data" nor access to "the equipment used for the processing". The principle thus covers both logical security (authentication, authorization concepts) and physical security (premises, hardware, storage media).

3 Relationship to further obligations

Article 5(1)(f) GDPR interlocks with a range of further obligations under the GDPR:

  • Data protection by design (Article 25 GDPR): the security principles must be taken into account as early as the selection and design of the processing systems.
  • Processing on behalf of a controller (Article 28 GDPR): the processor must provide sufficient guarantees as to the security of its processing.
  • Notification and communication (Articles 33 and 34 GDPR): where the protection of personal data is breached, obligations to notify and, where applicable, to communicate arise.
  • Data protection impact assessment (Article 35 GDPR): for high-risk processing operations, the security concept forms part of the assessment.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn