Encryption: making data unreadable without the key
Encryption turns readable data into a sequence of characters that is unintelligible without the appropriate decryption key. It is one of the most effective protections against the exploitation of stolen data.
Definition
There are two main types: symmetric encryption, where the same key is used to encrypt and decrypt data (fast, but requiring the key to be exchanged securely), and asymmetric encryption, which relies on a public key / private key pair, used in particular to secure web exchanges (HTTPS) or sign documents.
Properly implemented encryption protects data even if it is stolen: in theory, a stolen encrypted database remains unusable without the key. This is why the GDPR explicitly lists encryption among the measures that can reduce the impact of a data breach.
Key points
Symmetric or asymmetric
Two families of encryption, with complementary uses depending on whether data is being exchanged or stored.
Protection in the event of theft
Stolen encrypted data remains unusable for an attacker without the key.
A measure recognized by the GDPR
Encryption is one of the technical measures cited to reduce risk in the event of a data breach.
How BCIT can support you
Encryption of sensitive data is one of the measures we assess as part of GDPR compliance or support with ISO 27001.
Frequently asked questions
Is encryption mandatory under the GDPR?
It is not a universal obligation, but the GDPR explicitly cites it as an appropriate technical measure, especially for sensitive data.
What is the difference between encryption and hashing?
Encryption is reversible with the right key; hashing is not, which makes it more suitable for password storage.
Not ready to talk yet? Discover our cybersecurity assessment →
Is your sensitive data encrypted?
Let's identify together which data deserves stronger encryption.
Encryption: making data unreadable without the key
Encryption turns readable data into a sequence of characters that is unintelligible without the appropriate decryption key. It is one of the most effective protections against the exploitation of stolen data.
Definition
There are two main types: symmetric encryption, where the same key is used to encrypt and decrypt data (fast, but requiring the key to be exchanged securely), and asymmetric encryption, which relies on a public key / private key pair, used in particular to secure web exchanges (HTTPS) or sign documents.
Properly implemented encryption protects data even if it is stolen: in theory, a stolen encrypted database remains unusable without the key. This is why the GDPR explicitly lists encryption among the measures that can reduce the impact of a data breach.
Key points
Symmetric or asymmetric
Two families of encryption, with complementary uses depending on whether data is being exchanged or stored.
Protection in the event of theft
Stolen encrypted data remains unusable for an attacker without the key.
A measure recognized by the GDPR
Encryption is one of the technical measures cited to reduce risk in the event of a data breach.
How BCIT can support you
Encryption of sensitive data is one of the measures we assess as part of GDPR compliance or support with ISO 27001.
Frequently asked questions
Is encryption mandatory under the GDPR?
It is not a universal obligation, but the GDPR explicitly cites it as an appropriate technical measure, especially for sensitive data.
What is the difference between encryption and hashing?
Encryption is reversible with the right key; hashing is not, which makes it more suitable for password storage.
Not ready to talk yet? Discover our cybersecurity assessment →
Is your sensitive data encrypted?
Let's identify together which data deserves stronger encryption.