Data security refers to the protection of data against loss, manipulation and unauthorised access through technical and organisational measures.
Protection goals
The classic protection goals are confidentiality, integrity and availability. The GDPR adds the resilience of systems and the ability to restore data quickly after an incident.
Unlike data protection, data security covers all data, including trade secrets or technical data that does not relate to a person.
Implementation in practice
The appropriate level of protection depends on the risk, the state of the art and the costs of implementation. Established frameworks are ISO/IEC 27001 and the BSI's IT-Grundschutz.
Legal provisions
- Art. 5(1)(f) GDPR
- Principle of integrity and confidentiality.
- Art. 32 GDPR
- Security of processing.
- Art. 24 GDPR
- Responsibility for appropriate measures.