Is encrypting transmitted electronic messages compliant with the GDPR?
ANSWER
It is entirely appropriate for a controller (employer) to encrypt transmitted electronic messages containing an employee's personal data. Using this type of security measure follows from Article 32(1) GDPR and is lawful.
It should be noted, however, that while encrypting messages containing personal data is highly desirable and appropriate, a PESEL number should not be used as a password, given the relative ease of breaking this type of password.


