This clause sets the technical method used to scramble your data so only authorized people can read it. It matters because weak encryption is nearly useless—like a lock made of paper—while strong encryption protects data even if someone steals it. The clause should specify the exact encryption type (for example, "AES-256" for stored data and "TLS 1.2 or higher" for data moving between computers). Under UK GDPR and US data protection laws, you must use "appropriate technical measures," and courts recognize that outdated encryption standards (like old versions of SSL) don't meet this requirement.
Never accept vague language like "industry-standard encryption"—demand the specific standard be named (AES-256, TLS 1.3, etc.) and require it to be updated automatically if security experts declare it weak. Ask for proof they actually use this standard, such as a recent security audit report. If they can't name the standard or won't update it, they're cutting corners on security. ---
Frequently Asked Questions
What does this clause mean in simple terms?
This clause sets the technical method used to scramble your data so only authorized people can read it.
Why should I care about this clause?
It matters because weak encryption is nearly useless—like a lock made of paper—while strong encryption protects data even if someone steals it.
What are my options?
The clause should specify the exact encryption type (for example, "AES-256" for stored data and "TLS 1.2 or higher" for data moving between computers).
How does this affect small businesses?
Under UK GDPR and US data protection laws, you must use "appropriate technical measures," and courts recognize that outdated encryption standards (like old versions of SSL) don't meet this requirement.
