A hospital asks whether access controls that limit which staff can open patient records count only as organisational paperwork, or also as technical security measures under the GDPR. Which view is most accurate?
Select an answer to reveal the explanation.
Short Explanation
Who can open the file is a technical gate, not just a memo on the wall. Access control sits squarely among the technical measures that keep personal data from wandering into the wrong hands. Policies still matter—but the control itself is a tech measure.
Full Explanation
Article 32 GDPR contemplates measures such as access control as part of ensuring integrity, confidentiality, and resilience of processing systems. Restricting which accounts can retrieve patient records is a paradigmatic technical measure within technical and organisational measures (TOMs). Organisational measures remain complementary; they do not reclassify access control as non-technical paperwork.