The GDPR does not prescribe one product, architecture, or fixed checklist. It requires controllers and processors to select appropriate technical and organizational measures based on the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the likelihood and severity of risks to people’s rights and freedoms.
Security is therefore risk-based and processing-specific. Article 5 establishes integrity and confidentiality as a data-protection principle and makes controllers accountable for demonstrating compliance. Article 25 addresses data protection by design and by default, Article 28 governs important processor arrangements, and Article 32 sets the central security-of-processing duty. Encryption can be highly appropriate, but the Regulation lists it as one possible measure rather than a universal substitute for governance, minimization, access control, resilience, or testing.
A personal data breach has a precise legal meaning: a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. It can affect confidentiality, integrity, or availability and need not involve an external attacker. Conversely, not every cybersecurity incident is a personal data breach. Organizations need a process that first establishes what data and people are affected, then performs the notification risk assessments required by Articles 33 and 34.
Key points
Article 32 examplesWhere appropriate, pseudonymization and encryption; ongoing confidentiality, integrity, availability, and resilience; timely restoration after an incident; and regular testing and evaluation of security measures.
Accountability in practiceRecord the risk assessment and decisions, assign ownership, train authorized personnel, control processors and sub-processors, test safeguards, and update measures as processing and threats change.
Breach handlingA processor must notify the controller without undue delay after becoming aware of a personal data breach. A controller must document every personal data breach and, unless it is unlikely to result in a risk to people’s rights and freedoms, notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware. A notification made after 72 hours must include reasons for the delay. If the breach is likely to result in a high risk, the controller must generally communicate it to affected data subjects without undue delay, subject to Article 34’s exceptions.
Law versus guidanceThe GDPR text and applicable case law are authoritative. European Data Protection Board guidelines and ENISA publications help explain and implement the rules, but they are guidance rather than replacement legislation.
Important limitationA certification, security product, or recognized framework can support evidence of good practice but does not make processing automatically GDPR-compliant. Equally, a security incident does not by itself prove that the Regulation was infringed; the facts, risks, measures, and accountability evidence matter.