Appropriate risk-based security measures may include pseudonymisation, encryption, resilience, recovery and regular testing. Risk assessment must address accidental or unlawful loss, alteration, disclosure or access.
Interpretation and application must be checked against the official text and current version.
