Skip to main content

Encrypt, pseudonymize, or anonymize — Encrypt, pseudonymize, or anonymize personal data wherever possible

Most of the productivity tools used by businesses are now available with end-to-end encryption built in, including email, messaging, notes, and cloud storage. The GDPR requires organizations to use encryption or pseudeonymization whenever feasible.

PropertyValue
SectionData security
Ownerplatform

Mapped Controls

ControlTitle
SID-CRYPTO-01PKCS#11 HSM Key Protection
SID-CRYPTO-03AES-256-GCM Encrypted Keystore
SID-CRYPTO-02PRF Extension Key Derivation
SID-DATA-01SD-JWT Selective Disclosure
SID-DATA-06PII Field Encryption for User Records

Source: GDPR Checklist for Data Controllers