This clause requires the other party to scramble your data using mathematical codes while it sits in their storage systems—like locking files in a vault. If someone steals their hard drives or servers, the data remains unreadable without the encryption key. This matters because UK GDPR and US data protection laws expect companies to use "appropriate technical measures" to protect personal information; encryption at rest is now considered a standard, reasonable protection. For example, if a hospital stores patient records encrypted, a thief with a stolen server still cannot read the medical details.
Accept this clause—it's standard practice and protects you both. However, check who controls the encryption keys (the company or a third party?). If the company holds all keys, ask whether you can audit their key management practices or require they use industry-standard encryption like AES-256. ---
Frequently Asked Questions
What does this clause mean in simple terms?
This clause requires the other party to scramble your data using mathematical codes while it sits in their storage systems—like locking files in a vault.
Why should I care about this clause?
If someone steals their hard drives or servers, the data remains unreadable without the encryption key.
What are my options?
This matters because UK GDPR and US data protection laws expect companies to use "appropriate technical measures" to protect personal information; encryption at rest is now considered a standard, reasonable protection.
How does this affect small businesses?
For example, if a hospital stores patient records encrypted, a thief with a stolen server still cannot read the medical details.
