THE USE OF CERTIFICATION MECHANISMS AS AN EFFICIENT GUARANTEE OF PERSONAL DATA PROTECTION

被引:0
作者
Viguri Cordero, Jorge Agustin [1 ]
机构
[1] Univ Jaume 1, Fac Ciencias Jurid & Econ, Av Vicente Sos Baynat S-N, Castellon de La Plana 12071, Spain
来源
REVISTA CATALANA DE DRET PUBLIC | 2021年 / 62期
关键词
GDPR; certification; ISO/IEC; 27000; series; data protection; information security; personal data;
D O I
10.2436/rcdp.i62.2021.3571
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
The purpose of this paper is to analyse the certification mechanisms in force since the effective application of the General Data Protection Regulation (GDPR). As a starting point, we approach these mechanisms from their eminently technical focus and their approximation to the field of data protection law. Next, we examine the regulation of certification mechanisms in the GDPR and the initiatives that have recently been promoted in Spain, France and the United Kingdom by their respective data protection agencies. We then move on to the study of the ISO/IEC 27000 series of international standards, and more specifically ISO/IEC 27001 (information security) and 27701 (privacy information management) and their corresponding updates. Finally, the most immediate benefits of these initiatives and their scope for improvement in the short-term future are highlighted, once the most relevant limitations affecting effective compliance with the aforementioned regulation have been identified.
引用
收藏
页码:160 / 176
页数:17
相关论文
共 36 条
[1]  
Agencia Espanola de Proteccion de Datos, 2019, ESQ CERT DEL PROT DA
[2]  
Agencia Espanola de Proteccion de Datos, 2019, GUIA PRACTICA ANALIS
[3]  
Agencia Europea de Seguridad de las Redes y de la Informacion, 2017, REC EUR DAT PROT CER
[4]  
Alam Mehwish, 2018, LECT NOTES COMPUTER
[5]  
Asociacion Internacional de Profesionales en Privacidad, 2018, 2018 PRIV TECH VEND
[6]  
Calvo, 2019, ADAPTACION NUEVO MAR
[7]  
Carlos Alberto, 2019, TRATADO PROTECCION D
[8]  
Comite Tecnico de Normalizacion 320, CIB PROT DAT PERS
[9]  
Datoo Akber, 2018, COMPUT FRAUD SECUR, V9
[10]   From ISO/IEC27001:2013 and ISO/IEC27002:2013 to GDPR compliance controls [J].
Diamantopoulou, Vasiliki ;
Tsohou, Aggeliki ;
Karyda, Maria .
INFORMATION AND COMPUTER SECURITY, 2020, 28 (04) :645-662