Skip to content
compliancebase
GDPRChapter IV — Security of processing

Article 32

Security of processing

GDPR · Regulation (EU) 2016/679 · Last verified July 2026

Objective

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing as well as the risk to rights and freedoms, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

Points of focus

  • Implement measures appropriate to the risk to natural persons' rights and freedoms
  • Consider pseudonymisation and encryption of personal data where appropriate
  • Ensure ongoing confidentiality, integrity, availability, and resilience of processing systems
  • Ensure the ability to restore availability and access to personal data in a timely manner
  • Establish a process for regularly testing, assessing, and evaluating effectiveness of measures
  • Ensure persons acting under authority process data only on instructions

Implementation notes

Article 32 requires controllers and processors to implement security appropriate to the risk to people, not merely to the business. For SaaS, start from a personal-data risk view: what identifiers you hold, where they flow (prod, logs, support, AI vendors), and what harm misuse could cause. Implement layered measures — identity and access control, encryption in transit and at rest, network segmentation, logging and detection, backup and restore, vulnerability management, and vendor security — then regularly test whether they still work. Document why measures are appropriate given state of the art and cost. Align the same control set you use for SOC 2 CC6/CC7 with GDPR processing activities so customer DPAs referencing Article 32 have operational substance. Remember Article 32 also covers organisational measures: training, least-privilege admin processes, and instructions binding staff and subprocessors.

Audit tip: Provide a short Article 32 measures matrix: risk → measure → evidence artifact — reuse SOC 2/ISO proof where it genuinely covers personal-data processing.

Evidence auditors typically request:

  • Information security policy and risk assessment covering personal-data processing
  • Encryption standards (in transit / at rest) and key-management overview
  • Access control, MFA, and logging evidence for systems processing personal data
  • Backup restore tests and availability/resilience measures
  • Vulnerability management / penetration test summaries and remediation tracking

Common gaps

  • Security program exists for SOC 2 but never mapped to personal-data risk under Article 32
  • No restore testing for systems holding personal data
  • Encryption claimed without covering admin paths, backups, or support exports
  • No periodic evaluation of whether measures remain appropriate as the product scales

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 32This control
ISO 27001A.5.15, A.8.24, A.8.13, A.8.8Access, cryptography, backup, vulnerability management
SOC 2CC6.1, CC6.7, CC7.1, CC7.5Access, transmission, vulnerability detection, recovery
HIPAA164.312(a)(1), 164.312(a)(2)(iv), 164.312(e)(1)Access control, encryption, transmission security

Primary sources

Frequently Asked Questions

Article 32(1)(a) lists pseudonymisation and encryption as example measures to consider as appropriate. Encryption is widely expected for SaaS personal data at rest and in transit, but appropriateness is risk-based — document your decision and residual risk.

No. SOC 2 is an attestation against Trust Services Criteria for a system; Article 32 is a legal duty about personal-data security. SOC 2 evidence often supports Article 32 demonstrations but does not automatically equal GDPR compliance.

Both. Article 32 expressly obliges the controller and the processor to implement appropriate measures. Contracts (Article 28) allocate and describe measures but do not remove either party's duty.

A defined cadence to assess measure effectiveness — vulnerability scanning, restore tests, access reviews, pen tests, or control monitoring. Record results and remediations; 'set and forget' fails both GDPR and SOC 2 expectations.

Strong Article 32 measures reduce breach likelihood and impact. When a breach still occurs, Articles 33 and 34 govern notification. Security failures under Article 32 often feature in supervisory investigations of late or missing notifications.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: July 2026 · Primary sources linked above