Securing Sensitive Data: Consent, Encryption, and Access Controls
Secure high-harm personal data on websites with consent and choice records, encryption in transit and at rest, and least-privilege access controls under GDPR, DPDP, and CCPA.
- Consent and choice: Purpose-specific toggles, easy withdraw or limit, and server-side enforcement that tags actually read.
- Encryption: TLS in transit; at-rest encryption or tokenisation for IDs, biometrics, and payment data; keys in a KMS, not in git.
- Access: Least privilege, SSO and MFA for admins, just-in-time elevation, and audit logs on SPI tables.
- Vendors: Time-boxed access and contracts that require the same safeguards.
- Test: Tags blocked before consent, support roles cannot dump KYC buckets, backups stay encrypted.
Three controls that fail most often
Most sensitive-data incidents on websites trace back to weak consent records, missing encryption, or broad employee and vendor access. This guide covers those three layers with public requirements from GDPR Articles 7 and 32, ICO security guidance, India’s DPDP Act section 6 and 8 plus Rule 6, and CCPA section 1798.100(e) with the SPI limit rules in sections 1798.121 and 1798.135.
Use it alongside GDPR special category data, CCPA SPI compliance, DPDP sensitive data protection, and OneTrust classification. Minimisation and retention sit in our website checklist in this series.
1. Consent and choice that actually bind
GDPR and special category data
Where you rely on consent under Article 6, Article 7 requires that consent is freely given, specific, informed, and unambiguous, with a clear affirmative act. Pre-ticked boxes fail. Withdrawal must be as easy as giving consent. For Article 9 special category data, you usually need an Article 9(2) condition as well; explicit consent is one route and must clearly name the sensitive purpose.
EDPB Guidelines 05/2020 on consent elaborate the explicit-consent standard for high-risk processing. Log what the person saw, the version of the notice, the timestamp, and the purpose flags.
DPDP consent and notice
Sections 5 and 6 require notice and consent (unless a section 7 legitimate use applies). Consent must be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. Data Principals may withdraw consent, and processing that relies on consent should stop accordingly, subject to section 8 erasure rules. Keep purpose-specific consent for high-harm processing rather than one omnibus “accept all.”
CCPA notice and SPI limits
Section 1798.100 requires notice at collection for personal information and SPI categories, purposes, sale/share status, and retention. Section 1798.121 gives consumers a right to limit SPI use to permitted purposes; section 1798.135 and 11 CCR 7014 describe the “Limit the Use of My Sensitive Personal Information” link and Notice of Right to Limit when you use SPI beyond those purposes. Honour preference signals where the statute and regulations require it for sale/share and, where you map them, for limit requests.
Website consent checklist
- Separate toggles for analytics, ads, and any SPI or special category purpose.
- No consent buried only inside Terms of Service.
- Equal weight for reject / limit controls versus accept.
- Server-side enforcement: tags and APIs must read the same consent store the banner writes.
- Re-prompt when purposes change materially; do not recycle old consent for new SPI uses.
2. Encryption in transit and at rest
Legal baselines
GDPR Article 32 lists encryption and pseudonymisation as examples of measures that may be appropriate to the risk, alongside confidentiality, integrity, availability, resilience, restore capability, and regular testing. Controllers and processors must size measures to state of the art, cost, and risk.
The ICO’s encryption guidance states that the law does not always mandate encryption, but includes it as an example measure, and recommends encrypting personal information you store or transmit, with a policy, suitable algorithms and key sizes, and periodic review.
DPDP Rule 6 requires reasonable security safeguards that include, at minimum, securing personal data through encryption, obfuscation, masking, or virtual tokens mapped to that data, plus related access, logging, backup, processor-contract, and organisational measures.
CCPA section 1798.100(e) requires reasonable security procedures and practices appropriate to the nature of the personal information, aligned with Civil Code section 1798.81.5. CPPA materials on reasonably necessary and proportionate processing also cite encryption and automatic deletion as example safeguards for higher-impact data such as precise geolocation.
Website encryption checklist
- TLS on every page and API that handles accounts, payments, or forms (prefer current TLS 1.2+; follow current browser and ICO guidance on versions).
- HSTS on production hosts.
- Encrypt databases, object storage, and disk volumes that hold SPI or special category data (for example AES-256 class controls with managed keys).
- Application-level encryption or tokenisation for government IDs, biometric templates, and payment primary account numbers.
- Separate key management from the application (KMS/HSM); rotate keys; restrict who can decrypt.
- Encrypt backups and exports; ban unencrypted CSV dumps of SPI to laptops.
- Mask data in non-production environments (Rule 6-style obfuscation / virtual tokens).
3. Access controls that match the risk
Legal baselines
Article 32 and ICO security outcomes expect you to document who can access personal data, grant least privilege, authenticate users (stronger for privileged roles), remove access when no longer needed, and validate that technical permissions match the documented rights. Article 32(4) requires steps so people acting under the controller or processor only process on instructions.
DPDP Rule 6 expressly calls for access control over computer resources, visibility through logs, monitoring and review to detect unauthorised access, and retention of relevant logs for investigation (one year unless law requires otherwise).
Website access checklist
- Role-based access: support sees ticket text, not full KYC image galleries, unless justified.
- SSO and MFA for admin, CRM, warehouse, and cloud consoles.
- Just-in-time elevation for break-glass access to SPI stores; log every elevation.
- Quarterly access reviews; revoke leavers same day.
- Disable shared admin accounts.
- API keys and service accounts scoped to least privilege; store secrets in a vault, not in git.
- Audit queries against SPI tables; alert on bulk exports.
- Vendor access through time-boxed accounts under written contracts that require the same safeguards (DPDP Rule 6(f); GDPR Article 28; CCPA service provider terms).
Putting the three layers together on a typical stack
- Collect: consent or other lawful ground recorded; notice shown; unnecessary SPI fields removed.
- Store: encrypted volumes and field-level protection for the highest-harm columns.
- Use: application roles and query controls limit who sees plaintext.
- Share: processors get tokens or minimum fields, not full raw dumps.
- Exit: withdrawal, limit, or erasure flows revoke processing and remove access paths.
Test plan (lightweight)
- Attempt to load marketing tags before consent; they must not fire for restricted purposes.
- Confirm HTTPS and certificate validity on all collection endpoints.
- Verify a support role cannot download the full government-ID bucket.
- Restore a backup sample in an isolated environment and confirm SPI remains encrypted / masked.
- Pull access logs for one SPI table and confirm they are retained and reviewable.
Common gaps
- Consent logged in the CMP but ignored by server-side ETLs.
- TLS at the edge while internal service mesh moves SPI in clear text.
- Warehouse analyst roles with SELECT on every schema, including KYC.
- Encryption enabled in cloud defaults but application logs still print primary account numbers.
- SPI limit or withdrawal honoured in CRM but not in ad platforms.
Sources
- Regulation (EU) 2016/679, Articles 7 and 32; Article 9 for special category conditions.
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679.
- ICO: Encryption guidance; Security outcomes (identity and access control); A guide to data security.
- Digital Personal Data Protection Act, 2023, sections 5, 6, and 8; Digital Personal Data Protection Rules, 2025, Rule 6.
- California Civil Code sections 1798.100(e), 1798.121, 1798.135; Cal. Code Regs. tit. 11, section 7014.
Disclaimer
This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, sensitive-data controls, breach response, or other privacy and data-protection measures. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.
Last updated on 17 September 2026
