Information Security in Principles and Provisions of the EU Data Protection Law
Tihomir Katulić, Nikola Protrka
Abstract
Tihomir Katulić, Nikola Protrka
Abstract
Information security practices are a staple compliance mechanism ensuring the lawful processing and protection of personal data in the new European legal framework of Data Protection. Both the General Data Protection Regulation and the Regulation 2018/1725 on the protection of natural persons regarding the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data contain recognizable principles of and provisions regarding information security methods and practices. The purpose of this paper is to analyse the new EU data protection framework from the perspective of regulation of information security requirements, especially from the perspective of the data controllers and processors and their obligations to ensure conditions for lawful and secure processing of personal data and comply with potential data subject requests.
OpenAlex reports 5 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Information security practices are a staple compliance mechanism ensuring the lawful processing and protection of personal data in the new European legal framework of Data Protection. Both the General Data Protection Regulation and the Regulation 2018/1725 on the protection of natural persons regarding the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data contain recognizable principles of and provisions regarding information security methods and practices. The purpose of this paper is to analyse the new EU data protection framework from the perspective of regulation of information security requirements, especially from the perspective of the data controllers and processors and their obligations to ensure conditions for lawful and secure processing of personal data and comply with potential data subject requests.
Key concepts: Data Protection Act 1998, Data security, General Data Protection Regulation, Information protection policy, Personally identifiable information, Data Protection Directive, Information security, Computer security