A global organization is mandated to comply with the European Union's General Data Protection Regulation (GDPR). The security team is reviewing its data handling practices to ensure compliance. Which GDPR principle specifically requires that personal data be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures?
- AAccountability
- BData Minimisation
- CLawfulness, Fairness and Transparency
- DIntegrity and Confidentiality
Show answer & explanationAnswer & explanation
Correct answer: D. Integrity and Confidentiality
The GDPR principle of 'Integrity and Confidentiality' (also known as 'security') directly mandates the appropriate security of personal data, including protection against unauthorized or unlawful processing, and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
Why the other options are wrong
- A. This principle requires controllers to be responsible for and demonstrate compliance.
- B. This principle requires collecting only necessary data.
- C. This principle focuses on legitimate processing and clear communication to data subjects.
GDPR Integrity & Confidentiality
One of the seven key principles of GDPR, requiring that personal data be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures.
- Often referred to as the 'security' principle.
- Mandates technical (e.g., encryption) and organizational (e.g., policies) measures.
- Aims to protect data from both intentional and accidental harm.
Memory trick: GDPR: Remember 'My Little Pony Loves ICE-T' for the seven principles, where ICE-T covers Integrity, Confidentiality, and Accountability.