Our Partner Ivan Milošević and Senior Associate Andrea Cvetanović, together with Prof. Dr. Gojko Grubor, give a comprehensive analysis of how organisations must implement adequate organisational and technical measures proportional to risks assessed, in order to comply with GDPR. Controllers and processors must perform information security risk assessment and assess risks of business activities (processing activities) for personal data (assess the security of the processing of personal data), in order to be able to respond to risks for personal data and risks for rights and freedoms of data subjects, i.e., to apply adequate technical, organisational and legal measures to mitigate identified risks to an acceptable level.
The full analysis can be downloaded HERE