Our own servers in Europe · GDPR · Support in your language

Module 4 of 6 · GDPR · Block 4

Security measures

The GDPR requires security measures appropriate to the risk, without imposing a closed list like the previous regulation did.

Content reviewed on

Technical measures

Encryption, access control, backups, and pseudonymization of personal data, based on the processing risk.

Organizational measures

Internal policies, staff training, and confidentiality agreements for anyone accessing personal data.

Risk analysis

Assessing the risk of each processing activity to determine which security measures are proportional.

What an auditor usually asks for

  • Technical security measures in place
  • Personal data access policies documented
  • Staff data protection training
  • Risk analysis carried out per processing activity

How to cover this block in Kimobox

  1. 1Manage role-based permissions to limit personal data access in Kimobox.
  2. 2Log each employee's data protection training.
  3. 3Document the risk analysis for each processing activity as a version-controlled record.

Role-based permissions limit access to personal data to whoever actually needs it.

See Kimobox's infrastructure security

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Regulation (EU) 2016/679, General Data Protection Regulation EUR-Lex · Applicable since 25 May 2018
  2. Organic Law 3/2018 on Data Protection and guarantee of digital rights BOE-A-2018-16673 · 6 December 2018
  3. Spanish Data Protection Agency AEPD · Supervisory authority