Join our Newsletter — 33% off our NHI Course

Why do confidentiality and privacy need different governance rules?

They address different control problems. Confidentiality governs who may see information and under what disclosure conditions, while privacy governs how personal information is handled in contexts that create an expectation of privacy. If teams blur the two, they usually write weak data classes, inconsistent access rules, and confusing review criteria.

Why confidentiality and privacy split into different governance rules

Confidentiality and privacy are related, but they do not govern the same decision. Confidentiality asks who may see information and under what disclosure conditions. Privacy asks whether personal data may be collected, used, retained, shared, or repurposed in a way that respects legal, ethical, and contextual expectations. That difference is why one set of controls rarely satisfies both goals.

What confidentiality controls actually govern

Confidentiality governance is about restricting disclosure. In practice, that means defining data classes, setting access rules, and deciding who can read, copy, export, or forward information. The control question is usually, “Is this person or system allowed to see it?” That framing works for trade secrets, internal records, customer data, and other sensitive assets, but it does not fully answer whether handling the data is appropriate in the first place.

Confidentiality rules tend to center on access models, encryption, need-to-know, and exception handling. A system can be perfectly confidential and still collect more personal information than it should, keep it too long, or use it for a purpose the data subject would not expect. That is why confidentiality is necessary, but not sufficient, for privacy governance.

What privacy governance adds on top of secrecy

Privacy governs the conditions under which personal information is processed. It asks whether the collection, use, retention, sharing, and secondary use are justified in context, and whether the organisation can explain those choices clearly. The key distinction is that privacy is not only about hiding data, it is about legitimacy, proportionality, and contextual expectations around personal information.

That is why privacy rules often require different review criteria than confidentiality rules. A dataset may be non-public yet still privacy-sensitive because it profiles people, infers behaviour, or combines identifiers in ways that increase exposure. Conversely, some confidential business information has no privacy dimension at all. Treating both as the same control problem usually produces overbroad access policies and weak privacy review.

How blurred governance breaks in practice

When teams collapse confidentiality and privacy into one bucket, the first failure is usually weak data classification. Labels become too generic, so reviewers cannot tell whether they are approving disclosure controls or personal-data handling rules. The second failure is inconsistent access policy, where “sensitive” becomes a catch-all word that hides distinct obligations. The third is confusing review criteria, because one team checks permissions while another should be checking purpose, minimization, retention, and downstream sharing.

This is also where governance gaps show up in audits and incident response. If the same approval path is used for both secrecy and privacy, teams may miss whether a process is lawful, proportionate, or documented for personal data. A confidentiality review can confirm that access is limited; it cannot by itself confirm that processing is acceptable.

Risk and Threat Considerations

When confidentiality and privacy are governed with the same rulebook, organisations create blind spots in both access control and personal-data handling. The result is usually either excessive restriction that slows legitimate work, or weak review that lets sensitive personal information be processed for the wrong purpose or retained too long.

Failure mechanism: Teams apply disclosure controls where processing governance is needed, so they approve access without checking purpose, retention, minimisation, or secondary use. That mismatch produces data classes that are too vague and approval criteria that do not match the actual obligation.

Impact: The organisation can expose people to unnecessary processing, create audit and compliance findings, and still fail to meaningfully reduce disclosure risk because the wrong control is being reviewed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-3 — Access Enforcement Confidentiality governance depends on enforcing who may view sensitive information.
AC-6 — Least Privilege Confidentiality rules work best when access is narrowly scoped to need-to-know.
AR-2 — Privacy Impact and Risk Assessment Privacy governance requires evaluating personal-data processing risks and context.
Recommendation — Enforce AC-3 to limit disclosure to authorised subjects only. Apply AC-6 to minimise who can access sensitive information. Use AR-2 to assess whether personal data handling is justified and proportionate.
ISO/IEC 27001:2022 A.5.34 — Privacy and protection of PII The question hinges on separating PII governance from general secrecy controls.
Recommendation — Implement A.5.34 to govern personal data processing separately from confidentiality.
GDPR Article 5 — Principles relating to processing of personal data Privacy governance is about lawful, purpose-bound, minimised processing of personal data.
Article 25 — Data protection by design and by default Privacy needs built-in processing controls, not just access restriction.
Recommendation — Apply Article 5 to align personal-data handling with purpose limitation and minimisation. Build Article 25 requirements into systems so privacy is enforced by default.

Practitioner Guidance

What to verify: Separate the approval questions. For confidentiality, verify who can view the data and under what conditions. For privacy, verify why the data is collected, whether the use is proportionate, and whether retention and sharing are justified for the specific context.

Decision rule: If the issue is “who can see it,” treat it as confidentiality governance. If the issue is “should we collect, use, keep, or share it this way,” treat it as privacy governance. When both apply, require both approvals, not one blended review.

Practitioner takeaway: Good governance uses confidentiality to control disclosure and privacy to control processing; if those are merged, one of the two problems will usually be under-controlled.