Metaluxo
← Insights

GRC

GDPR Article 32: What Technical Measures Actually Look Like

That satisfy GDPR Article 32 — and most audits.

GDPR Article 32 says you must implement “appropriate technical and organisational measures” to protect personal data. Every audit, every regulator, and every customer security questionnaire asks about it.

But what does “appropriate” actually mean? At Metaluxo we map security controls to GDPR requirements for SMEs across the EU. Article 32 breaks down into seven specific measures. This post lists them with evidence requirements.


1. Pseudonymisation and encryption

Pseudonymisation means replacing identifying fields with artificial identifiers. It reduces risk but is not full anonymisation — the data can still be re-identified with the key.

Encryption means encoding data so that only authorised parties can read it. The standard is AES-256 for data at rest and TLS 1.2+ for data in transit.

Evidence: Encryption configuration screenshots, cipher suite documentation, and key management policy.


2. Ongoing confidentiality

You must ensure that only authorised people can access personal data. This means:

  • Role-based access control
  • Least-privilege principle
  • Regular access reviews (quarterly for most organisations)
  • Immediate removal of access when staff leave

Evidence: Access control policy, sample access review minutes, and HR offboarding checklist.


3. Integrity

You must protect personal data from unauthorised modification. This means:

  • Hashing or digital signatures for critical records
  • Version control for data that changes over time
  • Audit logs showing who changed what and when

Evidence: Integrity check procedures, sample audit logs, and change management records.


4. Availability

You must ensure personal data is accessible when needed. This means:

  • Redundant systems and failover
  • Tested backup and recovery procedures
  • Business continuity planning

Evidence: Backup test results, recovery time objective documentation, and business continuity plan.


5. Ability to restore availability

If a physical or technical incident occurs, you must be able to restore access to personal data in a timely manner. This is not the same as having backups — it is about recovery capability.

Evidence: Disaster recovery test results showing actual restoration times.


6. Regular testing

You must regularly test the effectiveness of your security measures. Common methods include:

  • Vulnerability scanning (monthly)
  • Penetration testing (annual or biennial)
  • Phishing simulations (quarterly)
  • Access control reviews (quarterly)

Evidence: Test schedules, test reports, and remediation records.


7. Policy enforcement

All of the above must be documented in policies and enforced through procedures. A policy that is not followed is worse than no policy — it proves you knew what to do and chose not to do it.

Evidence: Approved policies, training records, and internal audit reports confirming compliance.


The audit shortcut

If you have ISO 27001 certification, you have already implemented all seven measures. Map your ISO controls to Article 32 requirements and provide the mapping table as evidence. This is the fastest way to satisfy a GDPR audit.

At Metaluxo we run GDPR compliance assessments for SMEs, typically delivering an Article 32 control mapping and evidence pack in four weeks. If you are preparing for a GDPR audit or customer security review, book a free 30-minute consultation and we will tell you exactly what evidence you need.

Common questions

Is encryption mandatory under GDPR?

Not explicitly, but it is the most cited technical measure in GDPR guidance. If you do not encrypt personal data, you must prove an equally effective alternative.

What is the minimum encryption standard for GDPR?

AES-256 for data at rest and TLS 1.2 or higher for data in transit are widely accepted as the baseline. Older standards may be challenged.

Does GDPR require penetration testing?

Not directly, but Article 32 requires a process for regularly testing security measures. Penetration testing is the most common way to demonstrate this.

Related reading

Send us a message
Message us Book now