What does it mean when a vendor says your data is encrypted - and what should legal and privacy teams be asking beyond that?
In the fourth of six Mini Masterclass sessions, Seçil Bilgiç breaks encryption down into three states of data: at rest, in transit, and in process.
She explains why asking for 'all data to be encrypted at all times' doesn't quite work in practice - because data needs to be readable while it's being actively used.
She also looks at the difference between content data and metadata, and why control over encryptions keys matters - including what to consider when deciding whether your organisation or your vendor hold them.
In session 5: Contracts that create control.
