Many organisations confuse data protection with data security, yet the two concepts pursue different objectives that ideally complement one another.
- Data protection safeguards the rights and freedoms of natural persons when their personal data is processed.
- Data security, on the other hand, is concerned with protecting the confidentiality, integrity and availability of information and systems.
The GDPR has redefined the relationship between data protection and data security, making system security an essential component of data protection. While data security traditionally ensures confidentiality, integrity and availability, data protection extends these objectives to include transparency, intervenability (the ability to exercise data subjects’ rights) and non-linkability (protection against linking data across different services).