FieldRegister
Every field · Identifiers

Password, PIN or security answer

Credentials in a CRM are a breach waiting to be reported under Art. 33.

personal data
personal data?
confidential
sensitivity
never
AI use
contract
lawful basis usually relied on

Keep it how long

Never stored in a CRM.

The gap we see most

Portal passwords kept so support can log in as the customer.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Field Register.

Credentials stored GDPR Art.32 · GDPR Art.33 · ISO/IEC 27701:2019 6.6.4
GDPR Art.32 Security of processing

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rig...

Evidence an auditor accepts: The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation; Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate; Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome
GDPR Art.33 Notification of a personal data breach to the supervisory authority

On becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made la...

Evidence an auditor accepts: The internal breach register covering all breaches including those assessed as not notifiable, with the risk assessment recorded for each; The awareness timestamp per incident and the basis for it, since the 72 hours runs from awareness and not from confirmation or containment; Notifications as submitted, checked against the four content elements Article 33(3) requires
ISO/IEC 27701:2019 6.6.4 System and application access control

System and application access control must restrict access to information, provide secure log on, manage passwords, constrain privileged utilities and protect source code, and where the customer requires it the organization must provide secure log on capability for user accounts under that customer'...

Evidence an auditor accepts: Access restriction configuration for applications holding personal data; Secure log on mechanisms, including any capability offered to customers for accounts they control; Password management and privileged utility controls

Do this for your whole CRM

Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.

Build my field register

Payment card or bank account details · Child or dependant details