Encryption, logging and security
The law requires reasonable security measures proportionate to the sensitivity of the information. The choices below are common good practices.
Encryption
- In transit: TLS 1.2 minimum, TLS 1.3 preferred; HSTS.
- At rest: AES-256 (database, disks, backups).
- Keys: in a KMS or Vault, with rotation and separation of duties (who encrypts ≠ who administers).
Logs without personal information
Logs (Datadog, Sentry, ELK, CloudWatch) are a frequent leak source: emails in URLs, tokens in headers, full JSON payloads in stack traces.
import re
PATTERNS = [
(re.compile(r"[\w.+-]+@[\w-]+\.[\w.]+"), "[email]"),
(re.compile(r"Bearer\s+[A-Za-z0-9._-]+"), "Bearer [token]"),
(re.compile(r"\b\d{3}[ -]?\d{3}[ -]?\d{3}\b"), "[number]"),
]
def scrub(message: str) -> str:
for pattern, repl in PATTERNS:
message = pattern.sub(repl, message)
return message
Also configure redaction at the source (Sentry beforeSend, Datadog exclusion rules, Logstash processors) rather than relying on after-the-fact cleanup alone.
Audit and log retention
An audit log of access to PI (who, what, when), limited retention and restricted access to logs.