(a) General Security Obligations Under the LPPD
Article 12 of the LPPD mandates that data controllers and data processors implement all necessary technical and administrative measures to prevent unlawful processing or access to personal data and to ensure its retention securely. These measures must be determined in accordance with the guidelines and regulations published by the Authority.
The Personal Data Security Guide, published by the Authority, outlines examples of technical and administrative measures that data controllers and data processors may implement. These measures are not exhaustive and shall be assessed and applied by each data controller in an appropriate and proportionate manner, taking into account its organizational structure, sector, nature and scope of data processing activities, and the risks involved.
By way of example, technical measures include implementing cybersecurity precautions, creating authorization processes that allow employees to access only personal data relevant to their duties, and applying data masking techniques. Additionally, data loss prevention software must be used to prevent unauthorized data transfers.
As part of the administrative measures, it is necessary to identify existing risks and threats, regularly train employees on data security, and establish internal company policies regarding the protection of personal data. The amount and retention periods of personal data must be kept to a minimum, and contracts with third-party data processors should include provisions related to data security.
Furthermore, data controllers are obligated to establish an internal personal data breach response procedure or plan, setting out the roles, responsibilities, and steps to be followed in the event of a personal data breach. Such a plan is intended to ensure the timely detection, assessment, containment, and remediation of data breaches, as well as compliance with the notification obligations towards data subjects and the Board under the LPPD.
(b) Deletion, Destruction, and Anonymization of Personal Data
The Regulation on the Deletion, Destruction, or Anonymization of Personal Data sets out the procedures and principles for securely destroying personal data. Accordingly, all data controllers are required to delete, destroy, or anonymize personal data when the purposes of processing cease to exist and to take the necessary technical and administrative measures in this respect.
In addition, data controllers that are required to register with VERBIS must prepare and implement a Personal Data Retention and Destruction Policy, which sets out the applicable retention periods and the methods and timelines for deletion, destruction, or anonymization.
(c) Security Requirements for Sensitive Personal Data
The Guide on the Processing of Sensitive Personal Data establishes the information security standards and requirements for processing such data:
- For the security of sensitive personal data, systematic, clear, manageable, and sustainable policies and procedures must be implemented. Employees involved in data processing should receive regular training, confidentiality agreements should be signed, and access rights must be clearly defined. The access durations of authorized users must be periodically reviewed, and in the event of a job change or termination, their access rights must be immediately revoked.
- Where sensitive personal data is processed, stored, and/or accessed in electronic environments, appropriate technical and organizational measures must be implemented, including the use of cryptographic methods to protect the data, the secure and separate storage of encryption keys, and the logging and secure retention of records relating to all access and processing activities.
- In addition, security updates for the relevant systems should be continuously monitored, regular security and vulnerability tests should be conducted and documented, role-based access controls should be implemented for any software used to access the data, and at least two-factor authentication should be applied where remote access to such data is required.
- Where sensitive personal data is processed, stored, and/or accessed in physical environments, appropriate physical security measures must be implemented, including safeguards against risks such as fire, flooding, electrical failure, and theft, as well as controls to prevent unauthorized physical access to such environments.
- Where sensitive personal data is transferred, appropriate security measures must be implemented depending on the transfer method, including the use of encrypted corporate email or Registered Electronic Mail (KEP) for email transfers, encryption of data stored on portable media with cryptographic keys kept separately, secure transfer mechanisms such as VPN or sFTP for server-to-server transfers, and enhanced confidentiality and protection measures for transfers in paper form to prevent loss, theft, or unauthorized access.
(d) Security Requirements under the Cybersecurity Law No. 7545
In addition to the data security obligations under the LPPD, information security requirements may also arise under Cybersecurity Law No. 7545. This Law establishes a general framework for the protection of information systems, critical infrastructure and cyberspace against cyber-attacks and applies broadly to public and private entities operating in or providing services through cyberspace.
The Cybersecurity Directorate is empowered to require the implementation of technical and organisational cybersecurity measures, provide cyber incident response support, collect and evaluate log records, and conduct compliance audits. While the Law does not primarily regulate personal data processing, any personal data processed under its scope must comply with core data protection principles and be deleted, destroyed or anonymised once the relevant purpose ceases to exist.