Glossary Terms

Encryption

A security technique that converts readable information into a protected form that requires a key to access.
On this page

What is encryption?

Encryption is a security technique that transforms readable data, called plaintext, into an unreadable form, called ciphertext, using an algorithm and cryptographic key. Authorised users or systems can recover the original information only with the appropriate key. Encryption is commonly used to protect data in transit, at rest and, through specialised methods, during processing.

Encryption reduces the likelihood that stolen or intercepted data can be understood, but it is not a complete security solution. If an attacker obtains valid credentials, compromises an endpoint or gains access to the keys, encrypted information may still be exposed.

How does encryption work?

Symmetric encryption uses the same secret key to encrypt and decrypt data and is efficient for large volumes. Asymmetric encryption uses a public and private key pair and is often used for secure communications, identity and key exchange. Hashing is different because it creates a one-way value and is not designed to be decrypted.

The strength of encryption depends on approved algorithms, configuration, key length, implementation and key management. Custom or outdated cryptography can create false confidence.

Why is key management important?

Keys determine who can access encrypted data. They should be generated securely, stored separately, rotated, restricted and monitored. Organisations need procedures for backup, recovery, revocation and destruction. A strong algorithm provides limited protection when keys are shared widely or stored beside the encrypted data.

Customer-controlled or hardware-protected keys may reduce provider and sovereignty risk, but they also create operational responsibilities. Loss of a key can make legitimate data permanently inaccessible.

Where should encryption be used?

Encryption is commonly applied to databases, devices, backups, network traffic, file transfers and sensitive documents. The appropriate design depends on classification, threat model, performance and operational needs. Highly sensitive data may require field-level encryption or tokenisation in addition to full-disk or transport encryption.

Organisations should document coverage and exceptions, test configurations and monitor certificates and keys. Encryption should work alongside access control, logging, vulnerability management and incident response.

Frequently asked questions

Is encrypted data still personal data?

Yes, when the organisation or another party can decrypt or link it to individuals. Encryption is a safeguard, not anonymisation.

What is encryption at rest?

It protects data stored on disks, databases, devices or backups, reducing exposure if storage media or files are accessed without authorisation.

What is encryption in transit?

It protects data while moving across networks, commonly through protocols such as TLS, helping prevent interception and alteration.

Does encryption prevent all data breaches?

No. Attackers may access data after legitimate decryption, compromise accounts or steal keys. Multiple security layers are necessary.

Who should manage encryption keys?

Responsibility should be clearly assigned, with separation of duties, restricted administration, monitoring and tested recovery procedures.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.