A council measures ‘security’ solely by counting firewalls and ignores staff training, policies, and procedures that govern how personal data is handled. What does GDPR TOMs thinking require?
Select an answer to reveal the explanation.
Short Explanation
Firewalls without trained people and clear rules are like a vault with the combination taped to the door. GDPR talks about technical and organisational measures for a reason—both halves matter. Policies and training are part of the security story.
Full Explanation
Article 32 expressly refers to technical and organisational measures appropriate to the risk. Organisational measures include policies, procedures, and staff training that shape how personal data is accessed and handled. Limiting ‘security’ to perimeter technology alone misreads the legal standard and leaves foreseeable human-factor risks unaddressed.