The General Data Protection Regulation (GDPR) requires organizations to implement appropriate technical and organizational measures for applications that collect, process, or transmit personal information.
For example, Article 25 establishes “data protection by design and by default,” requiring systems to account for current and evolving security risks.


