Skip to main content
Category: Information Governance Principles

Principle of Protection

Simply put

The Principle of Protection refers to the idea that certain information should be safeguarded against unauthorized access, alteration, loss, or disclosure. The precise meaning varies significantly across different fields, ranging from data privacy and information security to broader concepts in law and humanitarian work. In a records and information governance setting, it generally concerns ensuring that records, particularly those that are sensitive, confidential, or contain personal data, are appropriately secured throughout their lifecycle.

Formal definition

The term 'Principle of Protection' does not map to a single, universally agreed definition in the evidence available and is used across multiple domains with distinct meanings. In information security contexts, protection is sometimes framed narrowly to exclude features usable only for mistake prevention, focusing instead on deliberate safeguards. In data protection and privacy regimes, protection principles are commonly expressed as a set of obligations governing the processing of personal data, which may include lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, and storage limitation, though the exact enumeration and enforceability depend on jurisdiction and applicable law. Other usages, such as the 'protective principle' in international law (a doctrine permitting a state to assert jurisdiction over conduct affecting its interests) and 'protection principles' in humanitarian standards (concerned with keeping people safe from violence, coercion and deprivation), are conceptually separate and should not be conflated with records or data protection meanings. Practitioners should confirm which framework or regime is intended before applying the term, as the scope, obligations, and legal weight differ materially across these domains.

Why it matters

The Principle of Protection is significant precisely because the term carries materially different meanings across domains, and misapplying it can lead to serious governance errors. In a records and information governance setting, protection typically concerns safeguarding records against unauthorized access, alteration, loss, or disclosure across their lifecycle, with particular attention to records that are sensitive, confidential, or contain personal data. Where the term is used loosely, practitioners risk applying controls suited to one framework while overlooking obligations that arise under another.

Who it's relevant to

Records managers
Records managers apply protection considerations when securing sensitive, confidential, or personal-data-bearing records throughout their lifecycle, from capture through disposition. They should confirm which framework governs a given record set, since data protection obligations, security controls, and organizational policy may each impose distinct requirements.
Data protection and privacy professionals
In privacy regimes, protection principles are often articulated as a set of obligations governing the processing of personal data. Privacy professionals need to determine which specific principles and enforcement mechanisms apply, as the exact enumeration and legal weight depend on jurisdiction and applicable law.
Information security teams
Security practitioners may encounter protection framed narrowly to focus on deliberate safeguards against unauthorized access or alteration, rather than features intended only to prevent inadvertent mistakes. Aligning security controls with records and privacy obligations helps ensure that protection is consistent across the information lifecycle.
Compliance and legal advisers
Because the term is also used in senses unrelated to records, such as the 'protective principle' in international law or 'protection principles' in humanitarian standards, compliance and legal advisers should verify which meaning is intended before applying it. Conflating these distinct usages can result in advice that misstates the applicable obligations.

Inside Principle of Protection

Protection of Sensitive Information
The Principle of Protection holds that a recordkeeping program should ensure a reasonable level of safeguarding for records and information that contain private, confidential, privileged, secret, classified, or otherwise sensitive content. The intent is to prevent unauthorized access, disclosure, alteration, or loss throughout the record's lifecycle.
Reasonable Level of Assurance
Protection is typically framed in terms of a reasonable rather than absolute level of safeguarding. The controls applied are generally expected to be proportionate to the sensitivity of the information and the risks it faces, recognizing that no protective measure can guarantee complete security.
Access Controls and Authorization
A core component is the restriction of access to records so that only appropriately authorized individuals can view, modify, or handle sensitive content. This often involves defining who may access what, under which conditions, and maintaining accountability for such access.
Confidentiality, Privacy, and Privilege
Protection addresses categories such as personal or private data, confidential business information, and legally privileged material. The specific obligations attaching to each category often depend on applicable laws, regulations, and organizational policy, which vary by jurisdiction and sector.
Lifecycle-Wide Safeguarding
Protection is intended to apply across the record lifecycle, from creation and capture through storage, use, and disposition. This includes safeguarding records during retention and ensuring secure handling at transfer or destruction, not solely at the point of creation.
Integrity and Trustworthiness Support
By guarding records against unauthorized alteration or tampering, protection helps preserve properties associated with trustworthy records, such as integrity and reliability, so that records remain usable as evidence of activity.

Common questions

Answers to the questions practitioners most commonly ask about Principle of Protection.

Is the Principle of Protection the same as information security?
No. Although the two overlap, the Principle of Protection is broader than information security in the technical sense. Information security typically focuses on safeguarding systems and data against threats such as unauthorized access, breach, or loss, often through technical and administrative controls. The Principle of Protection, as one of the Generally Accepted Recordkeeping Principles, addresses the protection of records that are private, confidential, privileged, secret, classified, or otherwise sensitive, and it frames protection as an accountability obligation within a broader recordkeeping and governance context. Security measures are among the means of achieving protection, but the principle also engages policy, classification, access control, and compliance considerations that extend beyond security operations alone.
Does the Principle of Protection mean all records should be locked down or restricted?
Not necessarily. Protection under this principle is intended to be proportionate to the sensitivity of the records concerned, rather than a blanket restriction on all records. Many records held by an organization may be routine or non-sensitive and do not warrant elevated safeguards. The principle is generally understood to call for appropriate levels of protection based on the nature of the information, such as whether it is private, confidential, privileged, or classified. Applying uniform restriction to all records can impede legitimate access and use, which itself may conflict with other recordkeeping principles concerning availability and accessibility. The aim is calibrated protection rather than maximal restriction.
How can an organization decide what level of protection a given record needs?
Organizations typically determine protection levels through a classification scheme that categorizes records according to their sensitivity, for example distinguishing public, internal, confidential, and restricted or classified material. The appropriate level often depends on legal, regulatory, contractual, and business considerations, which can vary by jurisdiction and sector. In practice, this involves identifying which records contain private, confidential, privileged, or otherwise sensitive information, mapping those categories to defined handling and access requirements, and documenting the rationale. Because requirements differ across jurisdictions and industries, many organizations align classification decisions with applicable privacy, security, and sector-specific obligations.
What controls are commonly used to give effect to the Principle of Protection?
Controls generally span administrative, technical, and physical measures. Administrative controls may include policies, classification schemes, access authorization procedures, training, and audit or monitoring practices. Technical controls often include access restrictions, authentication, and measures intended to preserve integrity and confidentiality. Physical controls may cover secure storage of paper records and physical media. The specific mix an organization adopts typically depends on the sensitivity of the records, the risks identified, applicable legal and regulatory requirements, and organizational policy. No single set of controls applies universally, and measures should be proportionate to the protection level assigned.
How does the Principle of Protection interact with legitimate access and disclosure obligations?
Protection must often be balanced against obligations to provide access, which can arise from freedom of information regimes, discovery in litigation, regulatory requests, or an individual's rights regarding their own personal information, depending on the jurisdiction and sector. The Principle of Protection is not intended to shield records from legally required disclosure. In practice, organizations typically reconcile these demands by controlling access according to authorization rather than preventing access altogether, and by applying protection in a way that supports, rather than obstructs, defensible responses to legitimate requests. Because access and disclosure requirements vary by jurisdiction, the balance struck should reflect the applicable legal framework.
How should protection be maintained across a record's lifecycle?
Protection is generally expected to apply throughout the lifecycle rather than only at a single point. This includes considering protection at creation and capture, during active use, through retention, and at disposition, whether that involves transfer, permanent preservation, or destruction. Sensitivity may persist or change over time, so protection requirements are often reviewed as records move through their lifecycle. At disposition, for example, secure handling of sensitive records may be required, and transfer to another custodian may carry protection obligations that continue after the records leave the originating organization. The appropriate approach depends on organizational policy and applicable legal and regulatory requirements.

Common misconceptions

The Principle of Protection guarantees that sensitive records will never be breached or disclosed.
The principle typically calls for a reasonable and proportionate level of safeguarding rather than an absolute guarantee. No set of controls can eliminate all risk of unauthorized access or loss, and the principle is generally understood in terms of assurance appropriate to the sensitivity and risk involved.
Protection is only about digital security, such as encryption or cybersecurity controls.
Protection encompasses more than technical security measures. It also concerns policy, access authorization, physical safeguarding of records in any format, and secure handling across the lifecycle. Depending on organizational policy, protective measures may span administrative, physical, and technical controls.
Protection means keeping records for as long as possible so nothing is ever lost.
Protection concerns safeguarding records against unauthorized access, alteration, or loss, and is distinct from retention. Retaining records longer than required does not necessarily improve protection and may increase exposure. Protection operates alongside, not in place of, retention and disposition decisions.

Best practices

Classify records by sensitivity so that the level of protection applied is proportionate to the confidentiality, privacy, or risk associated with the content.
Define and enforce access controls that limit handling of sensitive records to appropriately authorized individuals, and maintain accountability for such access.
Apply protective measures consistently across the entire record lifecycle, including during storage, use, transfer, and secure destruction, rather than only at creation.
Align protection controls with applicable legal, regulatory, and privacy obligations, recognizing that specific requirements depend on jurisdiction and sector.
Combine administrative, physical, and technical safeguards as appropriate, rather than relying on any single type of control.
Periodically review and adjust protective measures so they remain reasonable relative to evolving risks and the changing sensitivity of the records held.