SLIDE 7 The limitations of the GDPR and other laws Art 5.1(f)
Personal Data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures ('integrity and confidentiality'). No “availability” or “resilience” of systems. Defined by effect on data.
Art 32.1
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate…. (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services Confidentiality, integrity, availability, and resilience.
Art 33
Notification of Personal data breaches” “Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or
No reference to availability or resilience.
Art 83.4
Art 32 breach: 10,000,000 EUR / 2% Worldwide Turnover Wider requirements of Art 32.1 (availability, resilience) attract lower sanction but may never be notified in any event.
Art 83.5
Art 5 breach: 20,000,000 EUR / 4% Worldwide Turnover
Art 34
Express reference to systems and services. Cyber incidents such as ransomware and DDOS arguably not disclosable .
7