A library encrypts staff laptops but leaves shared network drives open to every staff login with no further access restrictions. Leadership claims encryption alone proves GDPR security compliance. What is the best assessment?
Select an answer to reveal the explanation.
Short Explanation
Encrypting the laptop while leaving the shared drive wide open is like locking the front door and leaving the garage up. GDPR wants measures that fit the risk—not one shiny control as a participation trophy. Layered, appropriate protection beats a single checkbox.
Full Explanation
Article 32 GDPR requires controllers and processors to implement appropriate technical and organisational measures taking into account the state of the art, costs, and the risks of processing. Encryption is a relevant measure but does not by itself prove adequacy when other high-risk exposures—such as unrestricted shared drives—remain. Security compliance is evaluated as a risk-based programme of measures, not as possession of one control.