Password, PIN or security answer
Credentials in a CRM are a breach waiting to be reported under Art. 33.
Keep it how long
The gap we see most
Portal passwords kept so support can log in as the customer.
What holding it is evidence for
Requirement text and artefacts from a human-verified corpus licensed to Field Register.
Credentials stored GDPR Art.32 · GDPR Art.33 · ISO/IEC 27701:2019 6.6.4
GDPR Art.32 Security of processingImplement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rig...
GDPR Art.33 Notification of a personal data breach to the supervisory authorityOn becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made la...
ISO/IEC 27701:2019 6.6.4 System and application access controlSystem and application access control must restrict access to information, provide secure log on, manage passwords, constrain privileged utilities and protect source code, and where the customer requires it the organization must provide secure log on capability for user accounts under that customer'...
Do this for your whole CRM
Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.
Build my field registerPayment card or bank account details · Child or dependant details