Security Measures
Document how you protect personal data.
Technical Measures
Select the technical security measures your organization implements:
Data stored encrypted
TLS/SSL for data transmission
Role-based access to data
Network protection
Monitoring for threats
Data recovery capability
MFA, strong passwords
Audit trails
Organizational Measures
Document the organizational controls in place:
Documented procedures
Data protection awareness
Due diligence on processors
Breach handling procedures
Security audits and reviews
Periodic permission audits
Categorizing data sensitivity
Employee and vendor NDAs
Template Security Statement
"We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, access controls based on the principle of least privilege, regular security assessments, and employee training on data protection practices."
Certifications & Compliance
If you have security certifications, include them:
Data Breach Notification
Your policy should explain what happens if a data breach occurs:
- • How you detect and investigate breaches
- • Notification to authorities per DPDPA requirements
- • When and how affected individuals will be notified
- • Steps taken to mitigate harm
💡 Be Honest, Not Specific
Don't include details that could help attackers (like specific software versions). Focus on the types of measures rather than implementation details.