0% found this document useful (0 votes)
3 views10 pages

CIPPE - Module 9

Module 9 of the European Data Protection online training emphasizes the importance of security measures in compliance with GDPR, highlighting the obligations of data controllers and processors. It outlines the necessity of implementing appropriate technical and organizational measures to safeguard personal data, considering factors such as risk assessment, state of the art technology, and cost of implementation. The module also discusses the significance of security controls, incident detection, and the engagement of data processors to ensure compliance and protect data subjects' rights.

Uploaded by

asd39499
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views10 pages

CIPPE - Module 9

Module 9 of the European Data Protection online training emphasizes the importance of security measures in compliance with GDPR, highlighting the obligations of data controllers and processors. It outlines the necessity of implementing appropriate technical and organizational measures to safeguard personal data, considering factors such as risk assessment, state of the art technology, and cost of implementation. The module also discusses the significance of security controls, incident detection, and the engagement of data processors to ensure compliance and protect data subjects' rights.

Uploaded by

asd39499
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

EUROPEAN DATA PROTECTION

ONLINE TRAINING TRANSCRIPT


MODULE 9: SECURITY OF PROCESSING

Introduction
Appropriate security measures can help to protect data and support compliance with the GDPR in many
ways. For example, failure to fully destroy data could lead to retention beyond the specified storage
period. Or improperly trained personnel could make changes to personal data that render it inaccurate.
The majority of data protection enforcement in Europe is related to security incidents. This module will
cover best practices for protecting against such incidents, and controller and processor obligations for
complying with the GDPR’s security obligations.

Appropriate technical and organisational measures


Introduction to security

Security is very important to European data protection law. It is often a prerequisite for achieving
compliance with data protection principles, whose infringements may result in fines up to €20,000,000
or 4% of the total worldwide annual turnover (whichever is higher). In addition, serious personal data
breaches can lead to bad press and media publicity, and civil and group claims.

German state DPA issues country's first GDPR fine (2018): The data protection authority of Baden-
Württemberg administered the first fine in Germany for violations of GDPR, according to a blog post
from Hogan Lovells' Chronicle of Data Protection. The DPA fined an unnamed social media provider
20,000 euros after it suffered a data breach. The social media company informed affected users of the
breach and the agency of its security failings. The DPA decided to penalise the company after the
agency discovered it stored passwords in plain text, a violation of Article 32 of the GDPR.

Controller and processor obligations

Article 32 of the GDPR addresses controller and processor security obligations. It states, ‘Taking into
account the state of the art, the costs of implementation and the nature, scope, context and purposes
of processing as well as the risk of varying likelihood and severity for the rights and freedoms of
natural persons, the controller and the processor shall implement appropriate technical and
organisational measures to ensure a level of security appropriate to the risk’. Click on the highlighted
text to learn more.

State of the art: The most cutting-edge technology is not necessarily the best choice for
security. As part of their risk assessment, controllers should reflect upon the consensus of
security professionals because security is an area of professional expertise with a long history of
developments. If a body of security professionals consider a particular control appropriate in a
particular circumstance, the controller should place weight on this consensus in deciding
whether to apply the control in its environment.

Costs of implementation: Controllers are not required to choose the most expensive security
controls; however, those implemented should reflect demonstrably good management
decisions.

©2023, International Association of Privacy Professionals, Inc. (IAPP)


2

Appropriate technical and organisational measures: The phrase ‘appropriate technical and
organisational measures’ is very broad. It covers everything from technical controls to
organisational policies and procedures, and it is left to the data controller and processor to
decide what is appropriate in the particular circumstances of their processing. The GDPR cannot
provide a fully detailed description of the controls that are required; otherwise, it would not be
future-proof. Instead, the GDPR lists some important results that these measures should bring
about, including pseudonymisation, encryption, confidentiality, integrity, and resilience.

Level of security appropriate to the risk: Recital 83 of the GDPR states, ‘In assessing data
security risk, consideration should be given to the risks that are presented by personal data
processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure
of, or access to, personal data transmitted, stored or otherwise processed which may in
particular lead to physical, material or non-material damage’. A risk-based approach likely will
require a risk assessment that determines controls for the entire information lifecycle. The risk
assessment will reflect the nature of the data that is to be processed; the context, purpose and
scope of the processing; the threat vectors that challenge the data, and the harm that may
result from a security breach. This means that controls become tighter and more sophisticated
when vulnerable and special categories of data are being processed. Conversely, non-sensitive
personal data may have only basic controls.

While controller and processor requirements are intentionally broad, the GDPR does provide some
specific suggested actions that may be appropriate to the risk. These include:

The pseudonymisation and encryption of personal data

The ability to ensure the ongoing confidentiality, integrity, availability and resilience of
processing systems and services

The ability to restore the availability and access to personal data in a timely manner in the
event of a physical or technical incident

And a process for regularly testing, assessing and evaluating the effectiveness of technical and
organisational measures for ensuring the security of the processing

Instructor video: Controller and processor obligations

So, what the laws says is when you are handling, processing personal data, you have to provide
appropriate technical and organisational security measures; where it generally does not say,
specifically, what security measures you have to have in place. And, so, that’s why those kinds of
conversations with your information security people can become kind of frustrating because they say,
do we have to have encryption? Do we have to hash? Do we have to put firewalls up? Do we have to
have this and that? And you kind of turn around and say, well, you have to have appropriate security.
And they struggle with that because they want you to tell them what is appropriate. But the law
deliberately avoids doing that because it’s very conscious of the fact that, firstly, lawyers, legislators,
we are not the best people to tell companies what’s the right security to have in place for their data.
And, secondly, if you think about how long it takes to pass a piece of a law, you can guarantee that
any security measures you legislate will be out-of-date almost the second they are enacted.

So, the law doesn’t do that. It just talks about appropriate security. But it tries to provide a little bit of
guidance. And it says that the security you provide has to be appropriate to the risk of your
processing. And that risk has to take into account the nature of your data, so the more sensitive the
data, the stronger the security measures you need. So, for those information security guys who are
asking you, do we need to encrypt data? If you’re handling sensitive personal data, the case for
encryption is going to become a lot stronger than if it’s ordinary personal data. You have to take into
account the context in which the processing is taking place. For example, if you are collecting data in
relation to the investigation of an employee who is accused of either breaching policy or doing some
kind of wrongdoing. That data, the context there is quite a sensitive context, so you’ve got a stronger
onus on you to keep that data more secure. You have to take into account the purpose of the
processing. What are you actually using the data for? And the scope of the processing. How much data
are you collecting? The more data you are collecting from a wider group of people, the more the need

©2023, International Association of Privacy Professionals, Inc. (IAPP)


3

to make sure you have stronger security in place. Because the consequences of losing a huge volume
of data are significantly greater than losing a smaller volume of data. So what the law says is you have
to take into account all that, and you also have to take into account the state of the art and the cost of
implementation. What the law recognises is there is no such thing as perfect security, and you can’t
achieve absolute security. What they are asking you to do is to have in place appropriate security that
takes into account the state of the art. In other words, what is the current state in technology, in the
market place, for use of security measures? And what are the costs of implementing those measures?
And you have to balance those against the nature, scope, context and purpose of the processing. So,
you don’t have to have world-class encryption for a very small data file of non-sensitive data. But,
equally, if you are having very sensitive, large-volume sensitive data, then, of course, the case is very
strong, and security becomes a lot clearer.

Security controls

Security controls are the actual processes used to ensure the security of an information system. These
controls must function properly, and the system must provide prompt notification if a control fails.
Security controls have four main attributes: confidentiality, integrity, availability and resilience.
Confidentiality, integrity and availability (known as CIA) should be well-known to information security
professionals. Resilience is new to EU data protection law, introduced through the GDPR. Click on each
attribute to learn more.

Confidentiality: Individuals, entities, systems or applications access data on a need-to-know


basis.

Integrity: Controls are in place to ensure data is accurate and complete.

Availability: Data is accessible when needed for a business activity.

Resilience: Data is able to withstand and recover from errors or threats.

CNIL issues 400K euro fine for GDPR violations (2019): France's data protection authority, the CNIL,
fined the real estate company Sergic 400,000 euros for violations of the GDPR. A complaint received by
the CNIL alleged users could access documents from other individuals on the site by modifying a URL.
The documents contained individuals' identity cards, tax notices, account statements and other
information. An investigation conducted by the DPA found Sergic was aware of the vulnerability since
March 2018. The DPA discovered Sergic did not implement any form of user authentication for those
who could access the documents, which factored into the decision to penalise the company.

Scenario A

Determine which of the attributes play a role in the following scenarios.

Gina is working from home today. She is trying to access client data she needs from her
organisation’s content management system; however, she is not able to remember her access
password. She emails Joseph in her company’s IT department to request the password.

Sharing passwords via email is against company policy, so Joseph provides Gina with a link that
will allow her to reset the password. The page prompts Gina to answer a series of security
questions that enable her to reset her password and access the secure client data.

Which of the security control attributes did you spot in the scenario? Select all that apply.

Confidentiality

Integrity

Availability

Resilience

Answer: confidentiality and availability

©2023, International Association of Privacy Professionals, Inc. (IAPP)


4

Feedback: The data within the content management system that Gina needs to do her job is
available, yet password protection and a protocol for resetting her password help to keep it
confidential.

A client at Gina’s organisation is planning a move and has asked her to change their contact
information within their system. After verifying their identity, Gina follows her organisation’s
procedures to change account data.

She uses a form within the organisation’s content management system to make the update.
Changing this form will prompt the same edits to propagate across the organisation’s system
and ensure client data remains consistent and accurate.

A few days after applying the update, the client again contacts Gina to say they are not moving
after all. Instead of recollecting the client’s original contact information, Gina quickly reverts to
the account’s previous state by using a roll-back option within the system.

Which of the security control attributes did you spot in the scenario? Select all that apply.

Confidentiality

Integrity

Availability

Resilience

Answer: integrity and resilience

Feedback: By using the correct form, Gina ensures that the integrity of the client’s data will be
protected across the organisation. The roll-back options within the content management system
help data withstand and recover from threats, including errors.

Security in practice

Security in practice within an organisation should take a holistic approach. Considerations may include
management and worker buy-in, a policy framework, the physical environment, information
technology, and incident detection and response. Click on each area to learn more.

Management and worker buy-in: An organisation should foster a culture of risk awareness and
respect for personal data throughout the entire employment lifecycle (from hiring and on-
boarding through termination).

A policy framework: Often referred to as an Information Security Management System. This is


the repository of all the organisation’s rules for confidentiality and security. It contains security
objectives and scope; security principles, standards and compliance requirements; and roles
and responsibilities. The policy should be approved by management, communicated to all
employees and relevant external parties, and reviewed periodically.

The physical environment: Considerations may include sophisticated entry control systems,
video surveillance, and lock-and-key and clean-desk policies.

EDPB “Guidelines 3/2019 on applying the GDPR in relation to processing personal data through
video devices,” adopted 29 January 2020 includes: Lawfulness of processing (legitimate
interest); disclosure of footage to third parties (general purpose, law enforcement);
transparency and information obligations (warning signs). Read the full guidelines here.

Technical measures: The importance of robust technical security measures cannot be over-
stated. These include data protection mechanisms, such encryption, antivirus and antispam
technology, firewalls, identity and access management, incident detection, data loss prevention,
two-factor authentication, logging and audit trails, vulnerability management, and regular
security code peer review. The GDPR specifically suggests implementation of pseudonymisation
and encryption.

©2023, International Association of Privacy Professionals, Inc. (IAPP)


5

Organizational Measures: Technical measures must be supplemented by organizational


measures. These include the procedures to ensure that staff are appropriately trained and even
recruited properly with background checks being performed on staff who will be handling the
most sensitive data, procedures to ensure data is handled appropriately through data
governance, data classification, data sharing procedures, data access reviews, clear desk
policies, data processing agreements, vendor due diligence and many more.

Incident detection and response: Regular testing of technical and organisational measures
assesses and evaluates their effectiveness. This also helps to ensure the ability to restore
availability and access to personal data in a timely manner if it is lost.

Scenario B

Read the following scenarios for examples of security in practice.

Buy-in: Colin’s organisation takes a holistic approach to securing its employees’ and clients’ personal
data. In doing so, it requires Colin, an executive, to follow the same security policies and procedures as
every employee. For example, Colin may use his personal mobile phone for business purposes only if
he agrees to the company’s bring-your-own-device policy, which allows the phone to be wiped if Colin
leaves the company.

Policy framework: Rules for confidentiality and security are posted on the company’s intranet within
the employee handbook. The handbook is always accessible to Colin and his co-workers. When the
employee handbook is periodically updated, the employees must sign a statement promising that they
have read and understood its contents.

Physical environment: Colin has access to hard copies of customer files that are required by local law
to be stored for a minimum of three years. Colin’s organisation has granted him special credentials to
access these files, which are stored in a locked room that can only be accessed with a key card.

Technical measures: The IT team at Colin’s organisation has protected his laptop with antivirus
technology. They run regular scans and updates, which usually occur automatically. This is one of
many protections used to secure the digital data stored on Colin’s computer and the company’s
network.

Organizational measures: The IT team has in place procedures to require all employees to keep a clear
desk and provides secure shredding disposal bins at multiple locations throughout the office to ensure
that staff have convenient access to be able to dispose of paper files that are no longer needed in a
secure manner.

Incident detection and response: The IT team and the data protection officer at Colin’s organisation
test their ability to detect and respond to a personal data breach by considering hypothetical scenarios.
For example, Colin could respond to a phishing scheme that tricks him into sharing his data
management system password with someone outside the company. Procedures that warn employees
of security issues may prompt employees to notify IT of a security breach. Learning of a breach quickly
may allow IT to prevent further loss.

Engaging processors
Article 28

A data processor is a third party that processes data on behalf of a data controller. The GDPR imposes
certain obligations on the controller and on the processor. Article 28 of the GDPR states, ‘The controller
shall use only processors providing sufficient guarantees to implement appropriate technical and
organisational measures in such a manner that processing will meet the requirements of this
Regulation and ensure the protection of the rights of the data subject’. In addition to a contract, the
term ‘sufficient guarantees’ covers assurance mechanisms, such as appropriate checking and vetting of
the processor by the supplier through a third-party assessment of certification validations before and
after creating a contract.

©2023, International Association of Privacy Professionals, Inc. (IAPP)


6

Vendor management

The GDPR’s requirements for vendor risk management may seem straightforward; however,
translating its requirements into practical action points may pose challenging, especially when:

Determining the extent to which the controller can rely upon the processor to attest and
monitor its own reliability and the extent to which the controller needs to evaluate third parties
before and after contracting, including conducting audits

Navigating complex contractual provisions

Negotiating contracts between two parties of unequal bargaining power or from EU and non-EU
jurisdictions

And navigating situations involving cloud computing that create difficulties knowing the precise
nature of data processing operations at any given moment in time

A checklist may provide issues to consider at the pre-contractual due-diligence stage and evidence that
the necessary steps were taken.

Processor contract due-diligence

To ensure processors provide appropriate security, controllers should exercise pre-contractual due
diligence through methods such as requests for information (RFIs) and requests for quotations (RFQs),
site visits, and audit observations. Pre-contractual considerations may include:

Processor’s data protection knowledge

Recent high-profile breaches

Recent and current investigations

Accreditations

The processor’s policy framework

And sub-processors

Processor contract

Processing by a processor shall be governed by a contract or other legal act under EU or member state
law that is binding on the processor. It may be based, in whole or in part, on standard contractual
clauses identified by the European Commission or supervisory authorities. Article 28 stipulates that the
contract must set out the subject matter and duration of the processing, nature and purpose of the
processing, type of personal data, categories of data subjects, and obligations and rights of the
controller.

Click here to learn about operational strategies for vetting and contracting with processors under the
GDPR

Contract stipulations

Click on each image to learn about processor contract stipulations required by the GDPR.

Process the personal data only on documented instructions from the controller unless required
by EU or member state law

Ensure that those individuals authorised to process the personal data have committed
themselves to confidentiality or are under appropriate statutory obligation of confidentiality

Implement appropriate technical and organisational measures, as set out in Article 32,
regarding security of processing

Assist the controller in fulfilling its obligation to respond to requests for exercising data subjects’
rights

©2023, International Association of Privacy Professionals, Inc. (IAPP)


7

Assist the controller in ensuring compliance with obligations specifically related to security and
prior consultation with supervisory authorities when required

Make available to the controller all information necessary to demonstrate compliance with
Article 28 (these processor rules)

Delete or return all personal data at the end of the processing services or if instructed by the
controller

Contribute to audits by the controller or another auditor chosen by the controller, and
immediately inform the controller if it believes any instruction infringes the GDPR or member
state law

Engaging sub-processors

The processor shall not engage a sub-processor without prior written authorisation of the controller.
Also, the same data protection obligations must be imposed on that sub-processor by way of a contract
or other legal act; however, the initial processor will remain fully liable if the sub-processor fails to fulfil
its data protection obligations.

Offshoring

In many controller-processor relationships, personal data is transferred offshore—in other words, it is


transferred internationally. If this is the case, an option for transferring data internationally as set out
in the GDPR should be used. These options are covered in more depth in Module 7 of this course. They
include: an adequacy decision for the recipient third country; or, if there is no adequacy decision,
appropriate safeguards, such as standard contractual clauses, ad hoc contracts approved by the
supervisory authorities and approved processor binding corporate rules.

Data breach notification


Article 4(12)

Article 4(12) of the GDPR defines a 'personal data breach' as a breach of security leading to the
accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal
data transmitted, stored or otherwise processed.

Click here to learn about operational responses to the GDPR’s requirements related to data breaches

Articles 33 and 34

Articles 33 and 34 specify controller and processor obligations for communicating when a personal data
breach has occurred. A processor must inform the controller without undue delay after becoming aware
of a breach. Depending on the circumstances, a controller must inform the supervisory authority and
may be required to inform the affected data subjects. Click on the arrows to learn more about
controller notification requirements.

Information provision to the supervisory authority

The controller is obligated to notify the SA of a personal data breach without undue delay (and
within 72 hours of becoming aware of it) if the breach is likely to result in a risk for the rights
and freedoms of natural persons. According to the European Data Protection Board, the
controller becomes aware of a breach “when that controller has a reasonable degree of certainty
that a security incident has occurred that has led to personal data being compromised”. The
communication with the supervisory authority should include: categories of affected data
subjects, the approximate number of data subjects and data records, the categories of affected
data records, the name and contact details of the data protection officer or other point of
contact, a description of likely consequences of the breach, and measures that have been taken
or will be taken in response to the breach. The controller also should keep documentation of all
the facts surrounding the breach to be able to prove compliance to the supervisory authority. In

©2023, International Association of Privacy Professionals, Inc. (IAPP)


8

a complex breach, it is acceptable to report in phases, once the fact surrounding the breach
becomes understood.

The Article 29 Working Party outlines general guidance on data breach notification, including
Guidelines on Personal data breach notification under Regulation 2016/679 (WP250). However,
it does not address all issues in sufficient detail. As a result, Guidelines 01/2021 on examples
regarding personal data breach notification were adopted to compliment WP 250 and provide
practice-oriented, case-based guidance using experiences gained by SAs since the GDPR
became applicable.

Further, as of 10 October 2022, any reference to WP250 rev.01 should now be interpreted as
Guidelines 9/2022 on personal data breach notification under GDPR (EDPB Guidelines 9/2022).
This guideline clarifies notification requirements concerning personal data breaches at non-EU
establishments.

Information provision to the data subject

Data subjects should be notified of a personal data breach without undue delay and in clear and
plain language if the breach is likely to result in a high risk to the rights and freedoms of those
individuals. Notification may not be necessary, however, if one of the following apply: there was
prior implementation of appropriate technical and organizational measures that rendered the
personal data unintelligible or encrypted; post-breach actions greatly reduce the risk to the
rights and freedoms of the data subjects; or individual notice requires disproportionate effort. In
this case, equally effective public notification is still required. Even if the controller decides not
to notify the data subjects, the supervisory authority may still decide that the controller needs
to do so.

In summary, if the processor suffers a breach, it must tell the controller. If the controller becomes
aware of a breach, it may be required to notify the relevant supervisory authorities and potentially the
data subjects concerned. A thorough risk assessment of breaches is essential to determine the impact
on the individual data subjects and thus deciding whether the breach requires notification to the
supervisory authority and the data subject.

NIS Directive
NIS Directive

The Directive on Security of Network and Information Systems (NIS Directive) went into force in May
2018. It is the first EU-wide cybersecurity law. While not specifically concerned with personal data, the
Directive aligns with the GDPR and indirectly bolsters the security of personal data within organisations
that are regulated by the Directive. Its three focuses include national capabilities, cross-border
collaboration and national supervision of critical sectors. Match each focus with its broader description.

National capabilities: Compel development of EU member state cybersecurity strategies and


structures.

Cross-border collaboration: Enhance cooperation between EU member states. A Cooperation


Group coordinates National Computer Security Incident Response Teams and develops best
practices.

National supervision of critical sectors: Improve security levels of essential services (energy,
water, transport, health and banking sectors) and digital service providers (online
marketplaces, online search engines and cloud computing services).

NIS2 Directive

The NIS2 Directive applies to medium and large entities. NIS2 boosts the concepts introduced by the
NIS Directive and will apply to covered entities as of 17 January 2025.

Key changes brought about by NIS2 include:

©2023, International Association of Privacy Professionals, Inc. (IAPP)


9

• Introduction of new classifications of covered entities, namely essential entities (e.g., energy,
banking, health, drinking water) and important entities (e.g., waste managements, food
production, manufacturers of medical devices, electrical equipment, computer, electronic and
optical products)
• Expansion of the list of sectors and activities subject to cybersecurity obligations
• Modification of breach notification requirements and introduction of voluntary coordinated
vulnerability disclosure for entities in scope

Quiz
1. CIAR stands for _____.

Continuity, information, access and risk assessment

Confidentiality, information, availability and risk assessment

Confidentiality, integrity, availability and resilience

Continuity, integrity, access and resilience

2. Drag and drop the correct phrase into the blank. ‘Taking into account the _____, the costs of
implementation and the nature, scope, context and purposes of processing…’ (Article 32).

appropriate technical and organisational measures

state of the art

a level of security appropriate to the risk

risk of varying likelihood

3. Drag and drop the correct phrase into the blank. ‘The controller and the processor shall implement
_____’ (Article 32).

appropriate technical and organisational measures

state of the art security

risks of varying likelihood

encryption appropriate to the risk

4. True or false: The most cutting-edge technology always is the best choice for security.

5. _____ must be included in a processor contract. Check all that apply.

The subject matter and duration of the processing

The method for destroying personal information following processing activities

The nature and purpose of the processing

The type of personal data

The categories of data subjects

6. True or false: A processor is responsible for implementing appropriate technical and organisational
measures to keep personal data secure.

7. True or false: A processor can decide how to process personal data outside of the documented
instructions from the controller.

8. A controller must notify the supervisory authority of a personal data breach if _____.

the breach is likely to result in a risk for the rights and freedoms of natural persons

©2023, International Association of Privacy Professionals, Inc. (IAPP)


10

the incident is categorised as a breach by information security personnel

the number of affected individuals exceeds 100

the organisation’s breach response plan is executed over 72 days following the data breach

9. A controller must notify the data subject(s) of a personal data breach if the breach is likely to result
in a high risk to the rights and freedoms of those individuals unless _____. Check the exceptions that
apply.

individual notice requires disproportionate effort

prior implementation of appropriate technical and organisational measures rendered the


personal data unintelligible or encrypted

post-breach actions greatly reduce the risk to the rights and freedoms of the data subjects

Quiz answers
1. Confidentiality, integrity, availability and resilience

2. State of the art

3. Appropriate technical and organisational measures

4. False

5. The subject matter and duration of the processing, The nature and purpose of the processing, The
type of personal data, The categories of data subjects

6. True

7. True

8. The breach is likely to result in a risk for the rights and freedoms of natural persons

9. Individual notice requires disproportionate effort, prior implementation of appropriate technical and
organisational measures rendered the personal data unintelligible or encrypted, post-breach actions
greatly reduce the risk to the rights and freedoms of the data subjects

*Quiz questions are intended to help reinforce key topics covered in the module. They are not meant to
represent actual certification exam questions.

©2023, International Association of Privacy Professionals, Inc. (IAPP)

You might also like