A security incident investigation shows personal data processing lacked basic integrity controls and access discipline. How does that finding map to GDPR processing principles?
Select an answer to reveal the explanation.
Short Explanation
When an incident reveals that nobody locked the doors or checked who could edit files, you are staring at the integrity and confidentiality principle in the wild. That principle is why appropriate security measures are not optional extras. Weak TOMs culture shows up as principle failure, not just ‘IT bad luck.’
Full Explanation
Article 5(1)(f) embeds integrity and confidentiality as a core processing principle, requiring appropriate security including protection against unauthorised processing and accidental loss or damage. Article 32’s technical and organisational measures give operational effect to that principle. A security incident that exposes absent integrity controls therefore maps directly to failure of the integrity and confidentiality principle, not merely to an isolated IT event.