New ICO GDPR Guidelines: On Passwords In Online ServicesJanuary 23, 2019 |GDPR
What is more, required under the GDPR?
The latest GDPR Guidelines from the Information Commissioner’s Office are relevant to anyone who owns a website whether they are using a (WordPress, WooCommerce or any other content management systems)
If your website has a feature of login, and you are taking data for this reason. No matter, they are customers, volunteers or the general public you have to consider the new guidelines from the ICO.
Initially, GDPR does not set any specific requirement about the passwords in online services, GDPR requires you to implement appropriate technical and organizational security measures to protect personal data.
This is the GDPR principle, it states “Processed in a manner that ensures appropriate security of the personal data. It includes protection against unauthorized or unlawful processing and accidental loss, destruction or damage, using appropriate technical or organizational measures.”
Consequently, Passwords are present to protect unwanted access to the systems that process personal data. Therefore, you need to consider the new ICO guidelines. While implementing the password strategy for particular circumstances, keeping the best alternative solutions for securing the passwords in mind. Any approach you chose must be secure from brute force attacks.
You can find more detailed information on the ICO website.