SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

GDPR Encryption

  Quote
Guest
Guest user Created:   Dec 23, 2017 Last commented:   Dec 23, 2017

GDPR Encryption

Does GDPR require the use of encryption for protecting/securing personal data? Aside from encryption, pseudonymization, and anonymization, are there other “acceptable” mechanisms for securing the data that’s GDPR-compliant?
0 0

Assign topic to the user

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Andrei Hanganu Dec 23, 2017

Answer:

The EU GDPR is quite broad when it comes to security of processing. It uses terms like ”appropriate” or “adequate” to refer to the safeguards that must be in place to protect personal data. The reason behind is that usually pieces of legislation are meant to be in force for a long period of time and remain unchanged as much as possible to ensure a stable legal environment. Referring to specific security measures would mean that the GDPR should undergo permanent changes and put unnecessary burden on the entities which must comply with it. Thus, the law maker actually leaves the controllers and processors to choose what security measures should be in place and only refers to as examples to “pseudonymisation” and “encryption” as examples (art.32(1)a EU GDPR).

To put it bluntly, as long as they are lawful, any security measures can be used to protect personal data, what matters is that you are able to ensure “confidentiality, integrity, availability and resilience “.

In our EU GDPR implementation toolkit https://advisera.com/eugdpracademy/eu-gdpr-documentation-toolkit/ there is a dedicated folder ( 8. Security of Personal Data) which contain various policies and procedures that you might find useful.

You may as well turn to ISO 27001 which is a very good framework for data security, and check out our article “Does ISO 27001 implementation satisfy EU GDPR requirements?” that you may find at https://advisera.com/27001academy/blog/2016/10/17/does-iso-27001-implementation-satisfy-eu-gdpr-requirements/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 23, 2017

Dec 23, 2017

Suggested Topics

Guest user Created:   May 03, 2021 EU GDPR
Replies: 3
0 0

Assistance with the toolkit

Guest user Created:   Oct 15, 2020 EU GDPR
Replies: 1
0 0

GDPR Implementation Questions

Guest user Created:   Jan 14, 2020 EU GDPR
Replies: 1
0 0

EU GDPR - DPO, DPIA & other questions