VadeLab
StatuteData Protection Act 2018

Section 107 — Data Protection Act 2018: Security of processing

Text of the provision Official document

Security of processing 107 1 Each controller and each processor must implement security measures appropriate to the risks arising from the processing of personal data.

2 In the case of automated processing, each controller and each processor must, following an evaluation of the risks, implement measures designed to—

a prevent unauthorised processing or unauthorised interference with the systems used in connection with it, b ensure that it is possible to establish the precise details of any processing that takes place, c ensure that any systems used in connection with the processing function properly and may, in the case of interruption, be restored, and d ensure that stored personal data cannot be corrupted if a system used in connection with the processing malfunctions.

Official source: legislation.gov.uk

There are no decisions in our collection citing this provision yet. As new judgments are published, they will appear here.

Search case law on this topic

See judgments from UK courts and tribunals with a plain-English summary and legal holding.

Explore case law →

Statutory text from an official public source. Informational content — does not replace advice from a qualified solicitor.