Encryption is the conversion of data by means of a key into a form that can only be read again with the matching key.
Forms of encryption
A distinction is made between transport encryption, for example using TLS for websites and emails, encryption of stored data on storage media and servers, and end-to-end encryption, where only the sender and recipient can read the content.
Besides the method itself, key management is decisive for effectiveness. The BSI's Technical Guideline TR-02102 provides guidance on the state of the art.
Legal significance
The GDPR expressly names encryption as an appropriate security measure. If a data breach only affects effectively encrypted data, there may be no need to inform the data subjects.
Legal provisions
- Art. 32(1)(a) GDPR
- Encryption as a security measure.
- Art. 34(3)(a) GDPR
- No obligation to inform data subjects where data is effectively encrypted.
- Recital 83 GDPR
- Encryption to mitigate risks.