Skip to content

Confidentiality

Origin domain
Law & Governance
Subdomain
information duties → Law & Governance
Aliases
Duty of Confidentiality, Nondisclosure Duty, Entrusted Information Protection
Related primes
Constraint

Core Idea

Confidentiality is a governed information relation in which an authorized holder may access protected information but is constrained in how it may use or disclose it. The obligation has a subject, protected content, permitted purposes, recipients, release conditions, exceptions, and breach consequences.

The canonical identity is narrower than the phrase’s everyday use. Information is not universally public; a holder obtains legitimate access; a rule restricts downstream use or disclosure; and the restriction persists across transfer until release, expiry, or an authorized exception. Confidentiality therefore binds use after access.

Structural Signature

  • Some information is designated protected relative to an identified subject or source.
  • A holder is authorized to know it but not thereby authorized to use or disclose it without limit.
  • A duty specifies permitted recipients, purposes, and forms of downstream use.
  • Release, expiry, consent, necessity, and overriding-duty exceptions are explicit.
  • Use or disclosure outside the permitted scope is a breach attributable to the holder.
  • The duty can be normative, professional, legal, contractual, or technically enforced.

What It Is Not

Secrecy can rely on nobody knowing the information. Privacy concerns control over a person or sphere. Encryption prevents unauthorized access but does not govern an authorized recipient's later disclosure. Anonymity hides identity rather than constraining information use.

  • Privacy governs a subject's claim over personal access or exposure; confidentiality governs a holder's duty after receipt.
  • Access Control decides whether an actor may access a resource; confidentiality also governs use after authorized access.
  • Secrecy may hide information without an entrusted-holder relation or defined authorized scope.
  • Contract requires a multi-party bundle, accepted enforcement regime, breach criteria, and remedies.
  • Encryption is one mechanism for enforcement, not the duty or relation itself.

Broad Use

Medicine, law, research, diplomacy, commerce, and system security preserve the same holder–information–purpose–disclosure relation. Institutions supply the rule, but the roles transfer intact.

A shared label or downstream consequence is insufficient; the load-bearing roles must survive.

Clarity

Confidentiality separates a specific relation from neighboring ideas that can produce similar observations. Secrecy can rely on nobody knowing the information. Privacy concerns control over a person or sphere. Encryption prevents unauthorized access but does not govern an authorized recipient's later disclosure. Anonymity hides identity rather than constraining information use.

Manages Complexity

The abstraction compresses recurring cases into one inspectable model. An analyst can track its roles, compare mechanisms, and locate which missing commitment invalidates an analogy.

Abstract Reasoning

Identify the candidate roles, test their defining relation, then challenge the nearest boundary case. Public data protected only against alteration has an integrity requirement, not a confidentiality requirement.

Knowledge Transfer

Medicine, law, research, diplomacy, commerce, and system security preserve the same holder–information–purpose–disclosure relation. Institutions supply the rule, but the roles transfer intact. Transfer is warranted only when the same causal, formal, or relational work survives.

Examples

Qualifying pattern. Confidentiality is a governed information relation in which an authorized holder may access protected information but is constrained in how it may use or disclose it. The obligation has a subject, protected content, permitted purposes, recipients, release conditions, exceptions, and breach consequences.

Boundary case. Public data protected only against alteration has an integrity requirement, not a confidentiality requirement.

Structural Tensions

T1 — Reach versus identity inflation. Broad use is valuable only while every defining role survives.

T2 — Observation versus mechanism. Similar outcomes can arise from neighboring mechanisms, so classification follows the relation and counterfactual rather than appearance.

Structural–Framed Character

Confidentiality is retained as a framed prime because its defining roles recur without depending on one field’s implementation.

Substrate Independence

Medicine, law, research, diplomacy, commerce, and system security preserve the same holder–information–purpose–disclosure relation. Institutions supply the rule, but the roles transfer intact. The roles do the same inferential work after the surface vocabulary changes.

Relationships to Other Abstractions

Local relationship map for ConfidentialityParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.ConfidentialityPRIMEPrime abstraction: Constraint — is a kind ofConstraintPRIME

Current abstraction Confidentiality Prime

Parents (1) — more general patterns this builds on

  • Confidentiality is a kind of Constraint Prime

    Confidentiality is the information-use species of constraint, restricting an authorized holder's admissible disclosures and downstream actions.

Hierarchy path (1) — routes to 1 parentless root

Neighborhood in Abstraction Space

Confidentiality has no computed distinctiveness yet.

Family — Unclustered & Miscellaneous (429 primes)

Nearest neighbors

Computed from structural-signature embeddings · 2026-07-26

Not to Be Confused With

Secrecy can rely on nobody knowing the information. Privacy concerns control over a person or sphere. Encryption prevents unauthorized access but does not govern an authorized recipient's later disclosure. Anonymity hides identity rather than constraining information use.

  • Privacy governs a subject's claim over personal access or exposure; confidentiality governs a holder's duty after receipt.
  • Access Control decides whether an actor may access a resource; confidentiality also governs use after authorized access.
  • Secrecy may hide information without an entrusted-holder relation or defined authorized scope.
  • Contract requires a multi-party bundle, accepted enforcement regime, breach criteria, and remedies.
  • Encryption is one mechanism for enforcement, not the duty or relation itself.

Solution Archetypes

No catalogued solution archetypes reference this prime yet.

Notes

(Canonical first draft from the adjudicated missing-node gate. Queued for Claude house-style re-authoring and independent citation review; no citations have been fabricated.)