Orientaciones para Administraciones Públicas ante el riesgo de brechas de datos personales

The Spanish Data Protection Agency has issued new guidelines for managing the risks of large-scale data breaches when public administrations exchange large volumes of personal data. This document acknowledges that the complex interconnection of infrastructures significantly increases the likelihood of incidents, requiring public bodies to accept the potential inevitability of such breaches. Consequently, it is essential to prioritize the implementation of specific measures from the initial design phase to minimize the impact on fundamental rights and society. It is crucial to adopt a coordinated management approach that includes joint failure scenario analyses and the application of appropriate protection techniques. The guidelines emphasize that total security cannot be guaranteed, so robust privacy safeguards are required at both the technical and organizational levels. This approach aims to drastically reduce the personal and social consequences arising from failures in interconnected systems, responding to the recent increase in breach notifications in the public sector. This analysis is vital for the field of open data because it establishes the necessary balance between administrative transparency and privacy protection. By regulating how data is shared and protected among public entities, it lays the groundwork for ensuring that open data initiatives do not compromise citizens' rights. Understanding these risks enables public data managers to develop secure interoperability frameworks, ensuring that information availability is not achieved at the expense of individual security.

Source: elderecho.com
Published on 2023-03-29