Defining Security Measures
Under the GDPR, both data controllers and data processors must implement appropriate technical and organizational security measures to protect personal data against accidental or unlawful destruction or loss, alteration, unauthorized disclosure or access.
To access and define security measures:
Security measures may be of the following types:
• Technical measures
Examples: Data partitioning, disaster recovery, anti-virus, Firewall
• Organizational measures
Examples: Policies and procedures, assignment of specific roles, Hardware maintenance
• Certification Systems
Example: ISO 27001, ISO 27018