Laws · GDPR ·art-5-par-1-pnt-f EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).
How it connects
Cited by
- Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack
- Guidelines 01/2022 on data subject rights - Right of access
- Centro De Estudio Dirigidos Delta, S.L.: Non-compliance with general data processing principles
- MAD COOL FESTIVAL S.L.: Insufficient technical and organisational measures to ensure information security
- hier
All 55
- Guidelines 02/2025 on processing of personal data through blockchain technologies
- EDPB Annual Report 2024
- VB v Natsionalna agentsia za prihodite
- SO Warszawa - III C 904/23
- UODO fines accounting firm €2,760 for email breach security failures
- UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- AEPD (Spain) - PS-00020-2025
- AKI (Estonia) - No. 2.1-1/24/397-890-38
- Garante per la protezione dei dati personali (Italy) - 385/2026
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security
- ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.: Insufficient technical and organisational measures to ensure information security
- UODO (Poland) - DKN.5131.27.2023
- Persónuvernd (Island) - 2025010358
- VG Düsseldorf: data subjects challenge district's sharing of personal data in water-law
- SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR
- EWHC (UK) - Johnson v Eastlight Community Homes Ltd
- Guidelines on processing of personal data through blockchain technologies
- EDPB Annual Report 2025
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)
- Report of the work undertaken by the ChatGPT Taskforce
- Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- EDPB Annual Report 2022
- EDPB Annual Report 2021
- Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak
- Court upholds €50,000 fine on Sociálna poisťovňa for sending sensitive data by ordinary
- X v Russmedia Digital SRL and Inform Media Press SRL
- BL v MediaMarktSaturn Hagen-Iserlohn GmbH
- ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts
- WM and Sovim SA v Luxembourg Business Registers
- UODO reprimands hospital for inadequate processor oversight and email security failures
- AEPD (Spain) - PS-00140-2025
- UODO (Poland) - DKN.5131.5.2025
- APDCAT sanctions Madremanya City Council for inadequate redaction of sensitive data in
- UODO reprimands mayor for disclosing data subject's data to company without legal basis
- VG Osnabrück - 7 A 170/24
- AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded
- Slovenian DPA fines controller €5,320 for leaving employee personal data documents
- HDPA (Greece) - 15/2026
- AEPD (Spain) - ps-0035-2025
- Permanent TSB plc: Insufficient technical and organisational measures to ensure information security
- Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste
- Docplanner Italy S.r.l.: Insufficient technical and organisational measures to ensure information security
- European Commission v Hungary
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access
- EDPB-EDPS Joint Opinion 4/2026 on the Proposal for a Cybersecurity Act 2 and the Proposal on amendments to the NIS 2 Directive
Related across sources
C-340/21 VB v Natsionalna agentsia za prihodite C-340/21 (VB v Natsionalna agentsia) Dec 14, 2023 Integrity and Confidentiality Principle Data Breaches Notification Obligation
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
C-687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht… Third Chamber Jan 25, 2024 Liability Integrity and Confidentiality Principle Data Breaches
C-231/22 État belge v Autorité de protection des données In Case C-231/22, the Court of Justice of the European Union interpreted Article 4(7) and Article 5(2) of the GDPR in response to a preliminary reference from the Brussels Court… Third Chamber Jan 11, 2024 Controllers Personal Data Public Authority
C-119/12 Judgment of the Court (Third Chamber), 22 November 2012.#Josef Probst v mr.nexnet GmbH.#Reference for a preliminary ruling from the Bundesgerichtshof.#Electronic communications — Directive 2002/58/EC — Article 6(2) and (5) — Processing of personal data — Traffic data necessary for billing and debt collection — Debt collection by a third company — Persons acting under the authority of the providers of public communications networks and electronic communications services.#Case C‑119/12. In Case C-119/12, the Court of Justice of the European Union interpreted Article 6(2) and (5) of Directive 2002/58/EC (the ePrivacy Directive) in proceedings between Josef Probst… Nov 22, 2012 Personal Data Processing Telecommunications
C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data