DECEMBER 2021CIOAPPLICATIONSEUROPE.COM 19What's "appropriate"?The requirement to process personal data securely is a key principle of the GDPR. In order to meet this obligation to secure data, the GDPR says that organizations must use "appropriate technical and organizational measures" to protect personal data. Technical and organizational measures are the physical and digital processes, procedures, or controls put in place to protect personal data both at rest and in transit, and also to detect when those measures have been compromised. This can include policies for governing what employees can and cannot do with personal data, policy monitoring, responsibilities around safe digital practice, access controls, firewalls, incident and event logging, and monitoring technologies. So far, so simple. But, when you dig into the details, things get a little complicated. While the broad language in the GDPR gives some flexibility to account for different risks, which may present themselves due to the uniqueness of data processing in any given organization, determining whether the technical and organizational measures taken are "appropriate" is difficult. If something does ultimately go wrong and the appropriate supervisory authority subsequently subjects your business to an audit or an investigation, their idea of what would have been considered "appropriate" may be very different to yours. For example, what constitutes "state of the art" when it comes to security? And, in the case of a data breach, you may end up with a regulator demonstrating the benefit of hindsight by (perhaps unfairly) assuming that something--your selection of controls, for instance--must not have been appropriate to prevent a breach that occurred. JAMES LLOYD, CYBER & PRIVACY PARTNER, LATHAM & WATKINScXoinsightsEnsuring Protection with Appropriate Technical and Organizational Measures James Lloyd
<
Page 9 |
Page 11 >