The technical and organisational measures set out here relate to the processor's own business premises, other facilities and its own operating resources.
Where processing activities take place on the business premises, in other facilities or using the operating resources of a subprocessor, the processor adopts the measures implemented there as its own.
Physical access control
Denying unauthorised persons physical access to data processing facilities
Implemented measures:
- Physical protection of server rooms and data centres
- Biometric access controls and smart card systems
- 24/7 monitoring by security personnel
- Visitor management and mandatory escorting
- Video surveillance of critical areas
System access control
Preventing unauthorised persons from using data processing systems
Implemented measures:
- Multi-factor authentication for all systems
- Role-based access control (RBAC)
- Regular review and updating of user permissions
- Automatic locking of inactive accounts
- Single sign-on (SSO) with central user management
Data access control
Ensuring that only authorised persons can access the relevant data
Implemented measures:
- Granular authorisation concepts at data level
- Principle of least privilege
- Regular access reviews and recertification
- Automated, role-based assignment of permissions
- Logging and monitoring of all access
Transfer control
Ensuring that personal data cannot be read without authorisation during transmission
Implemented measures:
- End-to-end encryption of all data transmissions
- TLS 1.3 for all web connections
- VPN connections for remote access
- Secure API communication using OAuth 2.0
- Regular review of encryption standards
Input control
Traceability of who entered, changed or removed which data and when
Implemented measures:
- Comprehensive audit logs for all data operations
- Versioning and change tracking
- Digital signatures for critical changes
- Automated notifications when data is changed
- Regular log analysis and anomaly detection
Instruction control
Ensuring that data is processed solely in accordance with the controller's instructions
Implemented measures:
- Clear processing policies and standard operating procedures
- Regular staff training
- Technical enforcement of processing rules
- Monitoring and alerting on deviations from the rules
- Documentation of all processing activities
Availability control
Ensuring that data is protected against accidental destruction or loss
Implemented measures:
- Redundant backup systems with geographic distribution
- Disaster recovery plans with defined RTOs/RPOs
- Highly available system architecture with failover
- Regular backup tests and restore exercises
- 24/7 monitoring and incident response
Separation control
Ensuring that data from different controllers is processed separately
Implemented measures:
- Multi-tenant system architecture
- Logical and physical separation of data
- Separate processing environments per customer
- Encryption with customer-specific keys
- Regular review of the separation measures
