Security of Personal Data Flashcards
What is controller obligation with respect to using appropriate technical and organisational measures?
Subject to state of the art/costs, controller shall implement appropriate technical and organisational measures.
True or False: A controller’s obligation to implement appropriate technical and organisational measures is absolute.
False.
This obligation is subject to state of the art/costs.
What are some examples of appropriate technical and organisational measures that can be implement to maintain security of personal data?
- Pseudonomisation
- encryption
- Confidentiality
True or False. The GDPR specifically defines what is appropriate security.
False.
The GDPR does not explicitly define appropriate security - why?
Security has to be appropriate to the risk of your processing.