[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjv6v__Z5eqtKozh8FKBRqWrTqo3m3MawYZAz3k921Ts":3,"faq-section-":60},{"tableOfContents":4,"markDownContent":5,"htmlContent":6,"metaTitle":7,"metaDescription":7,"wordCount":8,"readTime":9,"title":10,"nbDownloads":11,"excerpt":7,"lang":12,"url":13,"intro":14,"featured":4,"state":15,"author":16,"authorId":17,"datePublication":21,"dateCreation":22,"dateUpdate":23,"mainCategory":24,"categories":44,"metaDatas":50,"imageUrl":7,"imageThumbUrls":58,"id":59},false,"Article 30 1. g) of the RGPD requires the register to include \"*as far as possible, a general description of the technical and organisational security measures referred to in Article 32(1)*\".\r\n \r\nEach controller or processor has an obligation under **Articles 5 1. f) and 32 of the GDPR** to ensure data security by means of measures appropriate to the level of risk.\r\n \r\n### What are security measures?\r\n \r\nThese are all [necessary measures](https://www.dastra.eu/en/guide/what-security-measures-should-be-applied-under-the-gdpr/56344) to ensure the security and confidentiality of personal data.\r\n \r\nFor example, these may be **physical** security measures such as security of access to premises, or **informatic** security measures such as the installation of an anti-virus system, a binding password for data access, etc.\r\n \r\nFor each processing of personal data, it is necessary to take **appropriate measures** to **ensure a level of security appropriate to the risk to the rights and freedoms of the persons concerned** (invasion of privacy, discrimination, etc.).\r\n \r\n**The risk should not be assessed in relation to the company, but in relation to the data subject.\r\n \r\nGuaranteeing security means guaranteeing :\r\n \r\n- **confidentiality**,\r\n- **integrity**\r\n- and **availability** of data.\r\n\r\n**Security measures must therefore prevent illegitimate access to data, the unwanted modification of data and the disappearance of data**.\r\n \r\nTo ensure that the measures are appropriate to the risk, **these risks must be assessed**. To do this, it is necessary to identify the potential impact on data security, the sources of the risks, the possible threats and to assess whether the existing measures are sufficient. If not, they need to be increased.","\u003Cp>Article 30 1. g) of the RGPD requires the register to include \"\u003Cem>as far as possible, a general description of the technical and organisational security measures referred to in Article 32(1)\u003C/em>\".\u003C/p>\r\n\u003Cp>Each controller or processor has an obligation under \u003Cstrong>Articles 5 1. f) and 32 of the GDPR\u003C/strong> to ensure data security by means of measures appropriate to the level of risk.\u003C/p>\r\n\u003Ch3 id=\"what-are-security-measures\">What are security measures?\u003C/h3>\r\n\u003Cp>These are all \u003Ca href=\"https://www.dastra.eu/en/guide/what-security-measures-should-be-applied-under-the-gdpr/56344\">necessary measures\u003C/a> to ensure the security and confidentiality of personal data.\u003C/p>\r\n\u003Cp>For example, these may be \u003Cstrong>physical\u003C/strong> security measures such as security of access to premises, or \u003Cstrong>informatic\u003C/strong> security measures such as the installation of an anti-virus system, a binding password for data access, etc.\u003C/p>\r\n\u003Cp>For each processing of personal data, it is necessary to take \u003Cstrong>appropriate measures\u003C/strong> to \u003Cstrong>ensure a level of security appropriate to the risk to the rights and freedoms of the persons concerned\u003C/strong> (invasion of privacy, discrimination, etc.).\u003C/p>\r\n\u003Cp>**The risk should not be assessed in relation to the company, but in relation to the data subject.\u003C/p>\r\n\u003Cp>Guaranteeing security means guaranteeing :\u003C/p>\r\n\u003Cul>\r\n\u003Cli>\u003Cstrong>confidentiality\u003C/strong>,\u003C/li>\r\n\u003Cli>\u003Cstrong>integrity\u003C/strong>\u003C/li>\r\n\u003Cli>and \u003Cstrong>availability\u003C/strong> of data.\u003C/li>\r\n\u003C/ul>\r\n\u003Cp>\u003Cstrong>Security measures must therefore prevent illegitimate access to data, the unwanted modification of data and the disappearance of data\u003C/strong>.\u003C/p>\r\n\u003Cp>To ensure that the measures are appropriate to the risk, \u003Cstrong>these risks must be assessed\u003C/strong>. To do this, it is necessary to identify the potential impact on data security, the sources of the risks, the possible threats and to assess whether the existing measures are sufficient. If not, they need to be increased.\u003C/p>\r\n",null,263,2,"Security measures",0,"en","security-measures","Each data controller or processor has an obligation under Articles 5 1. f) and 32 of the GDPR to guarantee data security by means of measures appropriate to the level of risk.","Published",{"id":17,"displayName":18,"avatarUrl":19,"bio":7,"blogUrl":7,"color":7,"userId":17,"creationDate":20},38,"Paul-Emmanuel Bidault","https://static.dastra.eu/tenant-27/avatar/38/paul-emmanuel-bidault-150.jpg","2019-12-03T19:09:28","2023-12-27T13:37:37.491","2023-12-27T14:37:36.1633634","2023-12-28T13:54:45.2514574",{"id":25,"name":26,"description":27,"url":28,"color":29,"parentId":7,"count":7,"imageUrl":30,"parent":7,"order":11,"translations":31},21,"Glossary","Definition of every word used by Dastra","glossary","#643bb0","https://static.dastra.eu/tag/b308b9d3-37af-4e92-8354-ab8adec1740a/documentation-1000.png",[32,36,40],{"lang":33,"name":34,"description":35},"fr","Glossaire","La définition de tous les termes utilisés dans Dastra",{"lang":37,"name":38,"description":39},"es","Glosario","La definición de todos los términos utilizados en Dastra",{"lang":41,"name":42,"description":43},"de","Glossar","Die Definition aller in Dastra verwendeten Begriffe",[45],{"id":25,"name":26,"description":27,"url":28,"color":29,"parentId":7,"count":7,"imageUrl":30,"parent":7,"order":11,"translations":46},[47,48,49],{"lang":33,"name":34,"description":35},{"lang":37,"name":38,"description":39},{"lang":41,"name":42,"description":43},[51,54],{"typeMetaDataId":9,"value":52,"id":53},"https://www.dastra.eu/en/guide/what-security-measures-should-be-applied-under-the-gdpr/56344",111707,{"typeMetaDataId":55,"value":56,"id":57},3,"See the types of measures applicable",111708,[],56343,[]]