An IT team configures cloud storage buckets containing personal data to be publicly readable by default 'for convenience.' How should this default be evaluated under GDPR security requirements?
Select an answer to reveal the explanation.
Short Explanation
Leaving the bucket open to the world for convenience is the opposite of locking the filing cabinet. Appropriate technical measures mean defaults that protect, not defaults that publish. Famous cloud brands do not excuse that exposure.
Full Explanation
Appropriate technical and organisational measures under Article 32 include protecting personal data against unauthorised or unlawful access. Configuring storage containing personal data as publicly readable by default creates foreseeable unauthorised exposure and fails that standard. Neither operational convenience nor the reputation of a cloud provider converts insecure defaults into compliant security design.