# Integrity and Confidentiality (Article 5(1)(f) GDPR)

Data security as a principle of the GDPR: protection against unauthorized processing, loss and destruction; the relationship to Article 32 GDPR; the risk-based standard governing security measures.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.8-integritaet-und-vertraulichkeit
> Sprache: en



Article 5(1)(f) GDPR elevates data security to the rank of a principle. The provision requires that personal data be processed in a manner that "ensures appropriate security of the personal data". It identifies two objectives which the measures must serve: integrity and confidentiality.

<Callout type="info">
  **Key takeaways**

  * The principle establishes **data security** as a self-standing principle with two protection objectives: integrity (the data remaining intact) and confidentiality (protection against unauthorized knowledge of the data).
  * It covers not only deliberate interference but also **accidental** loss, destruction and damage (operator error, hardware failure, natural events).
  * The standard is **risk-based**: what constitutes appropriate security depends on the risk and on the nature, scope and context of the processing, as well as on the significance of the data.
  * Special categories of data under Article 9(1) GDPR give rise to a **heightened need for protection**.
  * The principle is given concrete shape by **Article 32 GDPR** and interlocks with Articles 25, 28, 33, 34 and 35 GDPR; an infringement may attract an administrative fine.
</Callout>

## 1 Overview [#1-overview]

### 1.1 The two protection objectives [#11-the-two-protection-objectives]

* **Integrity** denotes protection of the **intactness** of the data. Data must not be erased, destroyed or altered, in whole or in part, without authorization.
* **Confidentiality** denotes protection against **unauthorized knowledge of the data** and thus against unauthorized processing by third parties.

The principle covers not only deliberate interference but expressly also accidental loss, accidental destruction and accidental damage. It therefore extends to matters such as operator error, hardware failure and natural events.

### 1.2 Relationship to Article 32 GDPR [#12-relationship-to-article-32-gdpr]

The principle is given concrete shape by Article 32 GDPR. Article 32(1) GDPR obliges controllers and processors to implement appropriate technical and organizational measures ensuring a level of security appropriate to the risk. Under Article 32(1)(b) GDPR, ensuring the confidentiality, integrity, availability and resilience of the systems is among the central protection objectives.

### 1.3 Legal consequence [#13-legal-consequence]

An infringement of the principle renders the processing unlawful and may attract an administrative fine under Article 83(5)(a) GDPR; in addition, the notification obligations under Articles 33 and 34 GDPR may apply where there has been a personal data breach.

## 2 The standard of "appropriate" security [#2-the-standard-of-appropriate-security]

### 2.1 Risk-based approach [#21-risk-based-approach]

Whether the security measures are appropriate depends on the circumstances of the processing. The decisive factors are:

* the risk of unauthorized access,
* the nature, scope and context of the processing ([CJEU, judgment of 8 April 2014, C-293/12, C-594/12, Digital Rights Ireland, paras. 54 et seq.](https://curia.europa.eu/juris/document/document.jsf?docid=150642\&doclang=DE)),
* the significance of the data for the rights and interests of the data subjects.

Where financial data, data concerning health or other special categories of personal data under Article 9(1) GDPR are involved, the need for protection is heightened. Correspondingly higher requirements are to be imposed on encryption, access controls and logging.

### 2.2 Access to data and equipment [#22-access-to-data-and-equipment]

Recital 39, twelfth sentence, GDPR requires that unauthorized persons obtain neither "access to or use of personal data" nor access to "the equipment used for the processing". The principle thus covers both logical security (authentication, authorization concepts) and physical security (premises, hardware, storage media).

## 3 Relationship to further obligations [#3-relationship-to-further-obligations]

Article 5(1)(f) GDPR interlocks with a range of further obligations under the GDPR:

* **Data protection by design** (Article 25 GDPR): the security principles must be taken into account as early as the selection and design of the processing systems.
* **Processing on behalf of a controller** (Article 28 GDPR): the processor must provide sufficient guarantees as to the security of its processing.
* **Notification and communication** (Articles 33 and 34 GDPR): where the protection of personal data is breached, obligations to notify and, where applicable, to communicate arise.
* **Data protection impact assessment** (Article 35 GDPR): for high-risk processing operations, the security concept forms part of the assessment.

<Cards>
  <Card title="Data security" href="/docs/dsgvo-hub/einzelthemen/1.3.9-datensicherheit" description="Technical and organizational measures under Article 32 GDPR." />

  <Card title="Accountability" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.9-rechenschaftspflicht" description="Article 5(2) GDPR: demonstrating the security measures." />

  <Card title="Digital Rights Ireland" href="/docs/dsgvo-hub/rechtsprechung/1.4.5-eugh-digital-rights-ireland" description="CJEU C-293/12: security requirements in the context of data retention." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.