8. of Transfer I
We send personal data over email, but only within the company, so that should be fine, right?
Threat |
|
You’re not encrypting connections to the mail server, so someone could listen in. You are also storing unencrypted emails in mailboxes on your exchange that may be read by an administrator. |
|
GDPR |
Chapter 4, Art. 32 - 1. (a) Chapter 4, Art. 32 - 2. |
CCPA & CPRA |
CCPA 1798.100. General Duties of Businesses that Collect Personal Information (e) |
OECD |
Part 2, 11. Security Safeguards Principle |
Mitigations |
|
|