What Reasonable Technical Measures are Required to Protect Personal Data?
11th December 2024
‘Reasonable technical measures’ is an ambiguous term whose meaning varies depending on the nature and category of the data involved. The NCSC (National Cyber Security Centre) gives guidance for all kinds of technical measures that can be employed to protect personal data but it is up to each Controller to determine a proportionate and reasonable level of security. A case from Romania offers us a unique insight into what ‘reasonable technical measures’ could be, as the Regulator gave specific instructions to the Data Controller involved.
Case Details
On 18th November 2024, the ANSPDCP (or National Supervisory Authority for Personal Data Processing, aka the Romanian DPA) levied a fine of RON 99,516 (€20,000) against Altex Romania S.R.L, an online electronics retailer, for failing to implement sufficient security measures.
The data controller Altex Romania was informed by a third party that their data subject’s account data was being published online, including names, email addresses, account passwords and delivery addresses. On another occasion, Altex Romania was a victim of a technique called ‘credential stuffing’ where malicious actors use repeated login attempts to access user accounts and place unauthorised gift card orders. Altex Romania informed the ANSPDCP about these data breaches and took corrective measures to try to secure their customers’ data.
The ANSPDCP’s Investigation
The Romanian DPA took action and launched an investigation into the data breach. They found that Altex Romania failed to implement adequate technical and organisational measures to secure their customer’s data. This violates Article 32(1)(b) and 32(2) of the GDPR.
“Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk[…]
In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.” Source: EU GDPR
The ANSPDCP’s Recommendations
In an unusual move, the ANSPDCP told Altex Romania to implement the following corrective measures:
- implement new device login alerts, display logged-in devices in accounts, and enforce complex password policies with expiration intervals for all client accounts;
- establish a system to monitor inbound and outbound internet traffic on authentication platforms for all managed e-commerce sites and applications.
Source: GDPR HUB
This case is unusual because DPAs do not typically issue specific recommendations to Controllers, and the ANSPDCP does not usually publish full decisions. These recommendations are useful to us, as they provide specific actions that are deemed reasonable and proportionate by a DPA to protect against data breaches of this kind. This informs and prepares us to implement similar technical measures for the protection of customer data.
Here at Griffin House Consultancy, we issue a guide of minimum data security standards to our clients and review this guide regularly to make sure it is up to date. You can request a copy of the guide by emailing us at [email protected]. Always bear in mind that ‘reasonable technical measures’ will always vary depending on the kind of data involved, the nature of the organisation holding the data, and other factors.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.