A DPO documents technical and organisational measures at system launch but never revisits them after a major architecture change that expands personal-data processing. What does GDPR-aligned security require?
Select an answer to reveal the explanation.
Short Explanation
Security measures aren't a graduation photo you hang and forget. When the system grows or morphs, the locks and processes have to keep up. Document once, then revisit when the risk picture changes—that's how TOMs stay 'appropriate.'
Full Explanation
Appropriate technical and organisational measures are risk-based and dynamic. Major system changes that alter processing scope or risk typically require reassessment and update of TOMs so they continue to meet Article 32 expectations. Static documentation that ignores material change does not demonstrate ongoing appropriateness.