Which statement is FALSE concerning the use of technical security controls?
Privacy legislation commonly establishes a risk-based obligation to implement appropriate technical and organisational safeguards, rather than listing all specific technical security controls that must be deployed. GDPR Article 32 follows this approach by requiring security measures appropriate to the risk and giving non-exhaustive examples.
Community Discussion