Insights Information Commissioner’s Office publishes guidance on encryption under the GDPR

Contact

The new ICO guidance sits alongside its Guide to the GDPR and provides more detailed guidance for UK organisations on encryption under the GDPR.

The aim of the guidance is to help organisations understand the importance of encryption as an appropriate technical measure to protect the personal data they hold. Whether an organisation is a controller or a processor, encryption is a technique that can be used to protect personal data.

The guidance outlines the concept of encryption in the context of the GDPR’s integrity and confidentiality principle, and particularly Article 32 on security processing. It provides a summary of current forms of encryption and the considerations organisations should have when putting it in place, along with outlining the residual risks. Finally, it provides a number of scenarios where personal data is processed, outlining how encryption can be used to safeguard such data in respect of each scenario, and detailing some of the risks that remain.

The guidance also includes several recommendations, namely that where an organisation is storing or transmitting personal data, organisations should use encryption due to its widespread availability and relatively low cost of deployment. To access the guidance in full, click here.

Expertise