Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

UK Information Commissioner’s Office Issues Guidance on Use of Encryption and Passwords in Connection with GDPR

By Benjamin Jensen on November 26, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

The “security principle” under the General Data Protection Regulation (GDPR) requires that organizations process personal data securely by means of “appropriate” technical and organizational measures. This month, the United Kingdom’s Information Commissioner’s Office (ICO) issued new guidance focused on two specific measures the ICO recommends that companies consider in complying with the GDPR security requirements: encryption and passwords.

With respect to encryption, the ICO guidance notes that encryption is a tool that is both widely available and that can be deployed at relatively low cost. Further, the ICO notes that in numerous data security breaches, the harm caused could have been reduced or even avoided if encryption had been used. Accordingly, the guidance recommends the use of encryption for storage and transmission of personal data and suggests that the loss or destruction of unencrypted personal data may trigger regulatory action by the ICO.

In implementing an encryption policy, the ICO recommends that companies consider four factors: (1) choosing the right encryption algorithm (and regularly assessing whether the encryption method remains appropriate); (2) choosing an encryption key size that is sufficiently large to protect against an attack over the lifetime of the data; (3) choosing encryption software that meets current standards; and (4) keeping the encryption key secure, including having processes in place to generate new keys when necessary.

With respect to passwords, the ICO provides guidance on how organizational password policies can adhere to the security principle under GDPR. Among the topics addressed in the ICO guidance are recommendations for the following:

  1. How to store passwords?
  • Recommendation: Do not store passwords in plaintext –use a suitable hashing algorithm (or other mechanism).
  1. How users should enter passwords?
  • Recommendations:
    • Ensure that login pages are protected with HTTPS or an equivalent level of protection.
    • Make sure password hashing is carried out server-side, not client-side.
    • Do not prevent users from pasting passwords – while often seen as a security measure, preventing pasting of passwords impedes people from using password managers effectively.
  1. What requirements should be set for passwords?
  • Recommendations:
    • Set a minimum password length, but not a maximum length.
    • Allow the use of special characters, but do not mandate it.
    • Utilize “password blacklisting” to prevent users from setting a common, weak password.
  1. What should be done about password expirations and resets?
  • Recommendations:
    • Do not set password expirations unless absolutely necessary – having passwords that regularly expire encourages the use of a series of weak passwords.
    • Ensure that the password reset process is secure, that passwords are not sent over email, and that there are time limits on password reset credentials.
  1. What defenses can be put in place against attacks?
  • Recommendations:
    • Rate limit or “throttle” the number and frequency of incorrect login attempts.
    • Consider use of “CAPTCHAs”, whitelisting IP addresses, and time limits or time delays after failed authentications.
Photo of Benjamin Jensen Benjamin Jensen

Benjamin Jensen is partner in the firm’s Business Litigation Group, where he is a member of the Intellectual Property Litigation and Data Privacy and Security Practice Teams. His practice involves representing clients in complex business litigation matters in state and federal courts, with…

Benjamin Jensen is partner in the firm’s Business Litigation Group, where he is a member of the Intellectual Property Litigation and Data Privacy and Security Practice Teams. His practice involves representing clients in complex business litigation matters in state and federal courts, with a focus on matters involving intellectual property, data security, and contract disputes. Benjamin’s practice also includes representing health care providers and corporate clients in regulatory matters before the Connecticut departments of Health, Social Services, and Banking. Read his rc.com bio here.

Read more about Benjamin JensenEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo