Password Managers & Data Privacy – What Does the GDPR Require?

- GDPR requires complex and secure passwords.
- Password managers store passwords in an encrypted format.
- Local password managers offer higher security than cloud-based ones.
- Browser-integrated password tools are insecure.
- Companies should establish password policies and use password managers.
Whether for businesses or individuals, using passwords correctly and with sufficient variety often leads to a flood of credentials. It is becoming increasingly difficult to remember all these different passwords. Since using simple passwords repeatedly or writing them down unencrypted is not a viable solution, password managers are becoming an increasingly popular choice. But how effective are they from a data protection perspective?
Are password managers a helpful tool for data protection? And how does a password manager actually work?
Good password managers ensure that you neither have to remember nor write down your passwords, as they are stored in encrypted databases. Ideally, they also include built-in generators to create highly secure passwords if you prefer not to create them yourself. To activate the password manager, you only need a single master password. This password effectively unlocks your "password vault" and should never be forgotten. To meet the strict criteria of the GDPR, especially for sensitive access points, you should look for programs that provide a two-factor authentication feature. In this case, in addition to the password, users are required to provide another form of verification, such as a fingerprint or a TAN sent via SMS.
Differences between password managers
Many password tools automatically synchronize passwords across all your devices (computers, smartphones, tablets, etc.) and store them in the cloud. It is questionable whether this method of storage can be trusted without reservation. In terms of security, it is therefore preferable to use local password managersthat do not synchronize with the cloud. In this case, the passwords remain stored on the device itself rather than in the cloud. However, this reduces convenience, as you as the user are responsible for ensuring that your passwords are available on your smartphone or other devices when needed.
Most password managers are paid services. However, free tools can also be reliable. Local providers (without synchronization) are often free to use. Some of the best password managers that meet these criteria include LastPass, Keeper Security, and 1Password.
Apart from that, many browsers have integrated password tools. However, using them is not recommended: since Firefox, Safari, Chrome, and Edge are frequent targets for attacks, password managers and browsers should be kept separate. Furthermore, they usually do not include password generators. Another point against using built-in browser password storage is that passwords are often stored unencrypted on your device. This makes them easy for experts to extract—see our tips for data minimization while browsing.
Choosing the right password
To comply with the GDPR, which requires the protection of personal data through access restrictions like passwords, passwords—especially in companies—must be chosen so that they are not easy targets for hackers. You should avoid terms that can be traced back to the user, such as names or birth dates. Sequences like ABCD, 1234, and similar patterns are also not secure! It is advisable to choose a combination of uppercase and lowercase letters, numbers, and special characters. A password is also considered more secure the longer it is. Particularly long passwords of more than 24 characters are difficult for attackers to decrypt, even with the best technology. The supposed rule of changing passwords regularly is no longer undisputed. Frequent changes can be problematic, as new passwords are easier to forget or may be chosen to be weaker from the start in anticipation of an upcoming change. At the very least, you should change your password immediately if you suspect a hack, and otherwise about once a year. Many operating systems allow you to set up an automatic reminder for this.
Password managers for companies
Since the GDPR came into effect, it makes sense to have your company's data protection officer draft a password policy for you. Passwords for shared accounts should never be sent unencrypted via email or messenger between employees. Similarly, password lists should not be stored in shared folders on a server or in Google Drive without encryption. This is where the password manager comes into play again.
By having your corporate data protection officer develop a corresponding security concept, you ensure that you comply with this aspect of the GDPR and avoid fines and warnings.
In summary, a reliable password manager can certainly meet GDPR requirements, as it generates strongly encrypted passwords . Your login password should be long and include both numbers and special characters. Changing it at least once a year is also a proven best practice. With the necessary awareness of the subject and the help of password managers, complying with GDPR requirements should be effortless. Data protection and passwords? They are perfectly compatible!
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.



.avif)






