Back to glossary

Privacy

4 min read

Privacy is the protection of personal and sensitive information against unauthorised access, misuse or disclosure. It is the principle; the GDPR is the law that turns it into obligations, and personal data is what both apply to.

July 30, 2026
Compartir:

Privacy, in a security context, is the protection of the personal and sensitive information of individuals and organisations against unauthorised access, misuse or disclosure.

It is closely tied to control over personal information, and to compliance with the laws that govern it, such as the GDPR in the European Union or the CCPA in California.

What it involves

Confidentiality of personal information. Making sure that names, addresses, identification numbers, medical records, financial details and other sensitive information stay confidential and reachable only by people who are supposed to reach them, through encryption, access control and data handling policy.

Consent and transparency. Organisations have to obtain informed consent, where consent is the basis they are relying on, before collecting, processing or sharing personal data, and they have to say clearly what the data will be used for and who it will be shared with.

Protection against threats. Personal data has to be defended against internal and external threats: intrusion, malware, identity theft and data leakage. That is ordinary security work, applied to a category of data with legal consequences attached.

A worked example

An e-commerce company applies strict privacy policy to its customers’ data.

Payment information is encrypted in transit, account access requires a second factor, and the company runs periodic risk assessments and compliance reviews to confirm it is meeting its obligations.

The part that decides whether any of this works is less visible: knowing which systems hold personal data in the first place, including the logs and the analytics.

Privacy, GDPR and personal data

The three get used as if they were the same subject, and they are three different levels.

Privacy is the principle: a person’s control over their own information. It exists before any law does and it is broader than any of them.

The GDPR is the law that turns that principle into concrete obligations in the European Union, with its rights and its deadlines. In Spain it is complemented by the LOPDGDD and supervised by the AEPD.

Personal data is what it applies to, and its scope is wider than people assume: it includes online identifiers, IP addresses, cookie and device identifiers, and pseudonymised data, because that can be linked back to a person.

Why the order matters: a programme built on a narrow idea of personal data leaves out precisely the logs, the analytics and the identifiers where regulated data actually accumulates, which is usually where it would come from in a breach.

The practical instrument that connects the principle to a technical control is data classification: knowing what exists and where it is, before deciding how to protect it.

Where to read more

AEPD, privacy and security on the internet: practical guidance from the Spanish data protection authority.

Electronic Frontier Foundation, privacy: material on privacy principles and how they play out in practice.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.