# What is GDPR Security?

> GDPR security is the set of legal obligations and accountable practices used to protect personal data processed under the EU General Data Protection Regulation.

- Canonical URL: https://yellowcube.eu/glossary/general-data-protection-regulation-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The GDPR does not prescribe one product, architecture, or fixed checklist. It requires controllers and processors to select appropriate technical and organizational measures based on the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the likelihood and severity of risks to people’s rights and freedoms.

Security is therefore risk-based and processing-specific. Article 5 establishes integrity and confidentiality as a data-protection principle and makes controllers accountable for demonstrating compliance. Article 25 addresses data protection by design and by default, Article 28 governs important processor arrangements, and Article 32 sets the central security-of-processing duty. Encryption can be highly appropriate, but the Regulation lists it as one possible measure rather than a universal substitute for governance, minimization, access control, resilience, or testing.

A personal data breach has a precise legal meaning: a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. It can affect confidentiality, integrity, or availability and need not involve an external attacker. Conversely, not every cybersecurity incident is a personal data breach. Organizations need a process that first establishes what data and people are affected, then performs the notification risk assessments required by Articles 33 and 34.

### Key points

- **Article 32 examples:** Where appropriate, pseudonymization and encryption; ongoing confidentiality, integrity, availability, and resilience; timely restoration after an incident; and regular testing and evaluation of security measures.
- **Accountability in practice:** Record the risk assessment and decisions, assign ownership, train authorized personnel, control processors and sub-processors, test safeguards, and update measures as processing and threats change.
- **Breach handling:** A processor must notify the controller without undue delay after becoming aware of a personal data breach. A controller must document every personal data breach and, unless it is unlikely to result in a risk to people’s rights and freedoms, notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware. A notification made after 72 hours must include reasons for the delay. If the breach is likely to result in a high risk, the controller must generally communicate it to affected data subjects without undue delay, subject to Article 34’s exceptions.
- **Law versus guidance:** The GDPR text and applicable case law are authoritative. European Data Protection Board guidelines and ENISA publications help explain and implement the rules, but they are guidance rather than replacement legislation.
- **Important limitation:** A certification, security product, or recognized framework can support evidence of good practice but does not make processing automatically GDPR-compliant. Equally, a security incident does not by itself prove that the Regulation was infringed; the facts, risks, measures, and accountability evidence matter.

### Related terms

[Encryption](<https://yellowcube.eu/glossary/encryption/>) · [Cyber Resilience Act (CRA)](<https://yellowcube.eu/glossary/cyber-resilience-act/>)

### Sources

[EUR-Lex: Regulation (EU) 2016/679](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng) · [EDPB Guidelines 01/2021 on personal data breach notification](https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en) · [ENISA Handbook on Security of Personal Data Processing](https://www.enisa.europa.eu/publications/handbook-on-security-of-personal-data-processing)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

