Data security refers to the protection of data against risks such as unauthorised access, use, modification, disclosure, loss or destruction. Its primary objective is to preserve the confidentiality, integrity and availability of information. Confidentiality limits access to authorised users, integrity protects information from improper alteration, and availability ensures that data can be accessed reliably when required. This approach requires both technical and administrative measures against risks such as ransomware, data theft, system failures and human error.
Data security is not limited to personal information. Customer names, telephone numbers, identity details, payment records, survey results and employee information must be protected, along with corporate financial records, trade secrets and intellectual property. Certain information involving beliefs, health or sexual life may create greater risks and therefore require stronger protection. Türkiye’s data protection authority also states that special categories of personal data must receive stricter protection than ordinary personal information.
Data may be divided into categories such as qualitative and quantitative information. Occupation, colour and vehicle brand are categorical variables, while age, height and weight are quantitative variables. Categorical data may also be divided into nominal variables without a defined order and ordinal variables that follow a meaningful ranking. From a security perspective, however, information should primarily be classified according to its purpose, sensitivity and the potential consequences of unauthorised access.
Data security may be supported through access controls, multi-factor authentication, encryption, backups, network protection and regular security updates. Granting users only the permissions required for their responsibilities can reduce the potential impact of an incident. Logging system activity and monitoring unusual behaviour can also support earlier threat detection. Artificial intelligence may analyse large volumes of security information and identify anomalies, but it does not replace human oversight or fundamental security controls.
Cloud security is another important component of data protection. Responsibility within cloud environments is commonly shared between the service provider and the customer. Organisations must configure permissions, encryption settings, backups and retention policies correctly. Quantum computing is not currently a general method for storing or protecting information, but it is relevant because of the future risks it may create for existing encryption systems. NIST released its first three finalised post-quantum cryptography standards in 2024 to support protection against these potential threats.
Data security is also connected with legal and regulatory obligations. Under the GDPR, administrative fines for certain serious infringements may reach EUR 20 million or 4 per cent of an organisation’s total worldwide annual turnover from the preceding financial year, whichever is higher. This maximum penalty is not applied automatically to every data breach, as enforcement depends on the type, severity and circumstances of the infringement.
In Türkiye, Law No. 6698 on the Protection of Personal Data aims to protect fundamental rights and freedoms during the processing of personal information and regulate the responsibilities of organisations handling that information. Under Article 12, data controllers must prevent unlawful processing and access and ensure that personal data is stored securely. Compliance requires employee training, risk assessment, security policies and incident response planning in addition to technical controls. Effective data security management strengthens both regulatory compliance and stakeholder confidence.