6 ms·
Article 34.3.a seems to disavow the data processor of such requirement. The communication to the data subject referred to in paragraph 1 shall not be require
by medecau 6y ago
Article 34.3.a seems to disavow the data processor of such requirement.
The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met:
(a) the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
https://gdpr-info.eu/art-34-gdpr/ https://gdpr-info.eu/art-34-gdpr/
- SahAssar 6y agoI don't think hashing and encryption are considered equivalent in this case.
- GoblinSlayer 6y ago>(c) it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.