Technical measures
Encryption, access control, backups, and pseudonymization of personal data, based on the processing risk.
Organizational measures
Internal policies, staff training, and confidentiality agreements for anyone accessing personal data.
Risk analysis
Assessing the risk of each processing activity to determine which security measures are proportional.
What an auditor usually asks for
- Technical security measures in place
- Personal data access policies documented
- Staff data protection training
- Risk analysis carried out per processing activity
How to cover this block in Kimobox
- 1Manage role-based permissions to limit personal data access in Kimobox.
- 2Log each employee's data protection training.
- 3Document the risk analysis for each processing activity as a version-controlled record.
Role-based permissions limit access to personal data to whoever actually needs it.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Regulation (EU) 2016/679, General Data Protection Regulation EUR-Lex · Applicable since 25 May 2018
- Organic Law 3/2018 on Data Protection and guarantee of digital rights BOE-A-2018-16673 · 6 December 2018
- Spanish Data Protection Agency AEPD · Supervisory authority