QuestionQ31

Compliance with European Data Protection Law and Regulation

Considering the GDPR’s Article 32 requirements on the Security of Processing, which practice should the company implement?

  • A Encrypt the data in transit over the wireless Bluetooth connection.
  • B Include dual-factor authentication before each use by a child in order to ensure a minimum amount of security.
  • C Include three-factor authentication before each use by a child in order to ensure the best level of security possible.
  • D Insert contractual clauses into the contract between the toy manufacturer and the cloud service provider, since South Africa is outside the European Union.
Explanation

GDPR Article 32 requires technical and organisational measures appropriate to the risk and specifically identifies encryption of personal data as an appropriate safeguard. Encrypting data transmitted over the Bluetooth connection helps prevent unauthorised disclosure or access to children’s voice requests while they are in transit. GDPR, Article 32

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!