Principle of Protection
The Principle of Protection refers to the idea that certain information should be safeguarded against unauthorized access, alteration, loss, or disclosure. The precise meaning varies significantly across different fields, ranging from data privacy and information security to broader concepts in law and humanitarian work. In a records and information governance setting, it generally concerns ensuring that records, particularly those that are sensitive, confidential, or contain personal data, are appropriately secured throughout their lifecycle.
The term 'Principle of Protection' does not map to a single, universally agreed definition in the evidence available and is used across multiple domains with distinct meanings. In information security contexts, protection is sometimes framed narrowly to exclude features usable only for mistake prevention, focusing instead on deliberate safeguards. In data protection and privacy regimes, protection principles are commonly expressed as a set of obligations governing the processing of personal data, which may include lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, and storage limitation, though the exact enumeration and enforceability depend on jurisdiction and applicable law. Other usages, such as the 'protective principle' in international law (a doctrine permitting a state to assert jurisdiction over conduct affecting its interests) and 'protection principles' in humanitarian standards (concerned with keeping people safe from violence, coercion and deprivation), are conceptually separate and should not be conflated with records or data protection meanings. Practitioners should confirm which framework or regime is intended before applying the term, as the scope, obligations, and legal weight differ materially across these domains.
Why it matters
The Principle of Protection is significant precisely because the term carries materially different meanings across domains, and misapplying it can lead to serious governance errors. In a records and information governance setting, protection typically concerns safeguarding records against unauthorized access, alteration, loss, or disclosure across their lifecycle, with particular attention to records that are sensitive, confidential, or contain personal data. Where the term is used loosely, practitioners risk applying controls suited to one framework while overlooking obligations that arise under another.
Who it's relevant to
Inside Principle of Protection
Common questions
Answers to the questions practitioners most commonly ask about Principle of Protection.