7.1. The Service Provider implements appropriate technical and organizational measures to protect the Client's personal data, including:
Encryption of personal data in transit and at rest;Regular security assessments and penetration testing;Access controls and authentication mechanisms;Regular staff training on data protection and security.7.2. In the event of a personal data breach, the Service Provider shall notify the relevant supervisory authority and affected Clients in accordance with applicable law.