Skip to content
Literature · International Journal of Information Security and Cybercrime EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Trends in Interpretation of EU Data Protection Authorities of Cybersecurity Requirements Under the GDPR

Larisa GĂBUDEANU — International Journal of Information Security and Cybercrime

International Journal of Information Security and Cybercrime
DOI

How it connects

Full text

One of the main legal requirements for the adopting the GDPR was the technical and organizational security requirements, alongside the transparency and purpose limitation principles. The wide wording mentioned by the GDPR in terms of state-of-the-art security measures has given rise to a series of interpretations both in literature and by the data controllers and data processors. The manner in which national data protection authorities interpret this wording on a case-by-case basis is a good indicator in terms of interpretation, as the authorities look into the specific use case requiring preventive security measures. Thus, this research paper brings additional clarity in the interpretation of this legal requirement in terms of the risks and damages considered relevant for the specific data breach or lack of proper legal requirement implementation, given publicly available information in this respect. Further, the research paper highlights the number of use cases analyzed by different national data protection authorities and the views of each national data protection authority.

Similar Content