Article 32 GDPR : Security of Processing Through Risk-Appropriate Measures
Article 32 requires the controller and processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk: pseudonymisation and encryption, ongoing confidentiality/integrity/availability and system resilience, ability to restore access after incidents, and regular testing and evaluation.
Appropriate Technical and Organisational Measures (Art. 32 GDPR)
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: the pseudonymisation and encryption of personal data; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
The assessment of appropriateness is not static: it must consider the evolving state of the art, implementation costs, and the operational risks to individuals. The exact same statutory obligation applies directly to processors within their assigned processing perimeter.
- Encryption & pseudonymisation: cardinal statutory safeguards explicitly referenced in the GDPR text.
- CIA Triad: confidentiality, integrity, availability — plus ongoing system resilience and disaster recovery capabilities.
- Continuous improvement: regularly test, assess, and evaluate security controls (audits, penetration testing, backup restoration drills).
- Security by default across IT components: strict access control, comprehensive logging, patch management, and verified backups.
- Synergy with Article 33: robust security measures form the essential foundation for timely breach detection and 72-hour notification.
Recognised frameworks: ENISA guidelines and approved certifications or codes of conduct (Articles 40-43) provide authoritative benchmarks for demonstrating appropriateness. For small organisations, an operational baseline includes: full-disk and backup encryption, mandatory MFA on administrative accesses, centralised password policies, regular patching, verified disaster recovery drills, and a structured security incident log.
Verified Official Sources
General Data Protection Regulation — EU Reference Legal Framework
Consult official source →See Also in the Legal Framework
Articles 33 & 34 GDPR : Personal Data Breach Notification Procedure
Personal data breach notification obligations under Article 33 GDPR: notifying the supervisory authority without undue d...
Article 28 GDPR: Data Processing Agreement & Mandatory Clauses
Comprehensive guide to Article 28 GDPR: mandatory clauses of the Data Processing Agreement (DPA), controller and process...
Article 25 GDPR : Data Protection by Design and by Default Principles
Practical implementation of Article 25 GDPR and EDPB Guidelines 4/2019: integrating data protection principles upstream ...