4 ms·
Whenever a company tries to sell you their GDPR compliance by stating data is "encrypted at rest" you should call bullshit. If the data is stored on servers tha
by Puts 5y ago
Whenever a company tries to sell you their GDPR compliance by stating data is "encrypted at rest" you should call bullshit. If the data is stored on servers that are online the data will never be at rest (until the day the servers are discarded) making this protective measure useless in the context of Schrems II.
The EDPB Guidelines from November 2020 says:
"where unencrypted personal data is technically necessary for the provision of
the service by the processor, transport encryption and data-at-rest encryption even taken together,
do not constitute a supplementary measure that ensures an essentially equivalent level of protection
if the data importer is in possession of the cryptographic keys"
https://edpb.europa.eu/sites/default/files/consultation/edpb_recommendations_202001_supplementarymeasurestransferstools_en.pdf https://edpb.europa.eu/sites/default/files/consultation/edpb...
- mschuster91 5y ago> Whenever a company tries to sell you their GDPR compliance by stating data is "encrypted at rest" you should call bullshit. "Encryption at rest" is part of any sensible GDPR compliance concept; the threat that is being defended against is theft or seizure of servers and in the case of portables like laptops and USB sticks also loss of them - without the keys or password, the data is useless.