Ailance Alt TM Logo

Four-eyes principle in data protection

The dual-control principle in data protection.

Categories:

Model for data protection officers

The dual-control principle means that important measures should not be the sole responsibility of a single person or carried out by a single person. The goal is to limit errors and opportunities for abuse, since the likelihood that a single person will be compromised is higher than the likelihood that two people will act in a fraudulent manner together.

The principle originally comes from the Quality management and authentication, but is also becoming increasingly important in the area of data protection.

A classic example of this principle is the so-called “second opinion” in medical decision-making. But dual-control procedures can also be found in banking and government administration.

The dual-control principle in its symmetric and asymmetric forms

For the data protection officer, the dual-control principle plays a particularly important role in, among other things, the design of a rights and roles framework—especially with regard to administrator rights—as well as in documenting deletion processes.

For example, this can be stipulated in the company’s data protection policies. This ensures that access to the email archive is granted only when two administrators are logged in. However, when implementing this, there is a risk that controls may become superficial if those responsible rely on one another. Therefore, a hierarchical organizational structure should also be maintained in accordance with the dual-control principle.

Standard software such as SAP has implemented the dual-control principle—particularly for HR infotypes—when modifying infotypes through the use of so-called lock indicators. A data record thus exists but is not considered complete until another authorized user unlocks it. This process can be configured in both a symmetric and an asymmetric variant.

In the asymmetric version, a user can create, modify, and delete records. These records are initially locked automatically. Another user can, in turn, lock and unlock them. Once User B has unlocked the records, User A can no longer modify them. This would only be possible again if User B locks the records once more.

In the symmetric version, both users have the same permissions, but these are reciprocal; that is, the user who created the records cannot grant access to them.

Implement the dual-control principle as TOM

Even though the GDPR Although the dual-control principle is not expressly required, it may be implemented as part of the technical and organizational measures (TOM) under Article 32 GDPR an appropriate means of ensuring the safety of the Processing represent.

In particular, when granting and using privileged access rights, approving authorization schemes, exporting large data sets, or during the final Deletion When it comes to personal data, the dual-control principle can help reduce the risk of operational errors, misuse, and unauthorized access.

Companies should therefore assess, as part of their risk analysis, for which processing operations additional oversight by a second person is appropriate and proportionate.

Further information: BSI Information Security Audit Guide, Version 4.0

Keywords:

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post: