The General Data Protection Regulation requires a risk-based approach to data protection, whereby organizations take into account the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons, and institute policies, controls and certain technologies to mitigate those risks. These "appropriate technical and organisational measures" might help meet the obligation to keep personal data secure, including technical safeguards against accidents and negligence or deliberate and malevolent actions, or involve the implementation of data protection policies. These measures should be demonstrable on demand to data protection authorities and reviewed regularly.
Appropriate Technical and Organizational Measures
Tags:
Related Stories
EU General Data Protection Regulation
A curated collection of tools, resources and analysis of the EU General Data Protection Regulation....
Blockchain and the GDPR: Addressing the compliance challenge
Several recently published EU and U.S. institutions' and authorities' research papers analyze the relationship between blockchain technology and the General Data Protection Regulation. Given the myriad possible uses for blockchain technology and the GDPR compliance challenges that that technology po...
GDPR Enforcement: Is it really about the fines?
In the lead up to the General Data Protection Regulation, so much of the focus was on fines and regulatory audits, and while that may have been a spark that lit a fire for many privacy organizations, it is becoming increasingly clear that data subjects themselves will have an enforcement role as wel...