Encryption and De-identification Tools

GDPR, AI Act and Data Act Compliance Tools

To deliver the technology and tools side of the often cited 'Iron Triangle' of Data Privacy DigiTorc partners with best of breed suppliers to provide data encryption, de-identification and intrusion detection solutions at every price point.

The GDPR, AI Act and Data Act don’t specify particular technologies or encryption standards but requires “state of the art” security, i.e. AES-256 encryption to ensure confidentiality and integrity of personal data along with robust key management.

The GDPR sets the bar for the sharing of personal data and for the protection the rights and freedoms of individuals whose personal data is being accessed, used to train AI models or when shared with third-parties.

Encryption at Rest

Solutions must be able to encrypt data at both a Network Drive level and on a File by File basis on each drive.  Our key Technology Partner for encryption technologies is eset.com, an award winning Global company with a local support desk.

Eset solutions can be configured to encrypt Drives and Files to remove the possibility of data loss, theft or corrupting their integrity.

Encryption in Transit

For IT services we partner with Prevos Solutions, an award winning managed services provider who have a nationwide reach. Prevos offer a range of secure managed services for enterprises to implement end-to-end encrypted business processes and which incorporate Multi-Factor Authentication in implement enhanced protection along with the support of an excellent customer help desk.

Data De-identification

In addition to Drive and File level encryption whether at rest or in motion, the personal data that is contained within Files and Datasets must be afforded additional protection too when they are being accessed by authorised users or for analytic purposes.

A variety of automated tools are available to identify personal data and special category personal data within files and emails and apply one or other de-identification technique to anonymise, pseudonymise or de-identify this personal data entirely before use.

This is important for AI development teams who plan to train their AI Models with datasets, files and emails containing personal data and when the individual consent of data subjects is impractical to obtain.

De-identification of personal data is also a requirement when datasets containing personal data are shared under the Data Act, e.g. when transfers are necessary between public and private entities for research purposes.

Talk to us about recommending off-the-shelf or  bespoke encryption, pseudonymisation and de-identification solutions that best match your business needs and data processing use cases.

 

PeopleProcessTools
ESET logo
PrevosSolutionsBannerHeader
Scroll to Top