Fiche 45/54
Part 5 — Operational Obligations & Sanctions
Intermediate
Reviewed 2026-08-23
Security of Processing: Technical Measures (Art. 32)
Security of Processing: Technical Measures (Art. 32)
⚡ In 30 seconds
Under Article 32(1), taking into account the state of the art, the costs of implementation, and the risks of varying likelihood and severity for natural persons, controllers and processors must implement appropriate technical measures to ensure a level of security appropriate to the risk, encompassing confidentiality, integrity, availability, and resilience.
| Technical Domain | Article 32 Benchmark | Production Best Practice |
|---|---|---|
| Encryption (Art. 32.1.a) | Cryptographic protection of data in transit and at rest. | TLS 1.3 for all web and API endpoints; AES-256 or ChaCha20 for database volumes and backups. |
| Pseudonymisation | Preventing direct attribution without separately stored keys. | Tokenization of user IDs; isolated key management via cloud Hardware Security Modules (HSMs). |
| Resilience (Art. 32.1.b) | Ability to withstand DDoS, hardware failures, and systemic outages. | Multi-zone redundancy, container orchestration, rate-limiting, web application firewalls (WAF). |
| Restoration (Art. 32.1.c) | Restore availability and access to personal data in a timely manner. | Immutable air-gapped backups, tested Disaster Recovery Plans (DRP), Recovery Time Objective (RTO) metrics. |