Article 32
Security of processing
GDPR · Regulation (EU) 2016/679 · Last verified July 2026
Objective
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing as well as the risk to rights and freedoms, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
Points of focus
- Implement measures appropriate to the risk to natural persons' rights and freedoms
- Consider pseudonymisation and encryption of personal data where appropriate
- Ensure ongoing confidentiality, integrity, availability, and resilience of processing systems
- Ensure the ability to restore availability and access to personal data in a timely manner
- Establish a process for regularly testing, assessing, and evaluating effectiveness of measures
- Ensure persons acting under authority process data only on instructions
Implementation notes
Article 32 requires controllers and processors to implement security appropriate to the risk to people, not merely to the business. For SaaS, start from a personal-data risk view: what identifiers you hold, where they flow (prod, logs, support, AI vendors), and what harm misuse could cause. Implement layered measures — identity and access control, encryption in transit and at rest, network segmentation, logging and detection, backup and restore, vulnerability management, and vendor security — then regularly test whether they still work. Document why measures are appropriate given state of the art and cost. Align the same control set you use for SOC 2 CC6/CC7 with GDPR processing activities so customer DPAs referencing Article 32 have operational substance. Remember Article 32 also covers organisational measures: training, least-privilege admin processes, and instructions binding staff and subprocessors.
Audit tip: Provide a short Article 32 measures matrix: risk → measure → evidence artifact — reuse SOC 2/ISO proof where it genuinely covers personal-data processing.
Evidence auditors typically request:
- Information security policy and risk assessment covering personal-data processing
- Encryption standards (in transit / at rest) and key-management overview
- Access control, MFA, and logging evidence for systems processing personal data
- Backup restore tests and availability/resilience measures
- Vulnerability management / penetration test summaries and remediation tracking
Common gaps
- Security program exists for SOC 2 but never mapped to personal-data risk under Article 32
- No restore testing for systems holding personal data
- Encryption claimed without covering admin paths, backups, or support exports
- No periodic evaluation of whether measures remain appropriate as the product scales
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 32 | This control |
| ISO 27001 | A.5.15, A.8.24, A.8.13, A.8.8 | Access, cryptography, backup, vulnerability management |
| SOC 2 | CC6.1, CC6.7, CC7.1, CC7.5 | Access, transmission, vulnerability detection, recovery |
| HIPAA | 164.312(a)(1), 164.312(a)(2)(iv), 164.312(e)(1) | Access control, encryption, transmission security |
Primary sources
- GDPR Article 32: Regulation (EU) 2016/679, Article 32 — Security of processing