GDPR and Cybersecurity: What Article 32 Actually Requires
GDPR Article 32 mandates "appropriate technical measures" to protect personal data. Here is what that means in practice.
GDPR Is Not Just a Legal Problem
Most businesses treat GDPR as a legal and administrative issue — privacy policies, consent forms, data subject requests. But GDPR Article 32 has a specifically technical dimension that is often overlooked.
What Article 32 Requires
Article 32 of the GDPR requires organisations to implement "appropriate technical and organisational measures" to ensure a level of security appropriate to the risk. This includes:
- Pseudonymisation and encryption of personal data
- Confidentiality, integrity, availability of processing systems
- Resilience of processing systems and services
- Ability to restore availability and access to data in a timely manner after an incident
- Process for regularly testing and evaluating the effectiveness of security measures
What "Appropriate" Means
The regulation does not prescribe specific tools. Instead, it requires measures appropriate to the risk — taking into account the state of the art, implementation costs, and the nature of the data.
For most organisations processing personal data, "appropriate" means:
- Endpoint protection (EDR) on all devices processing personal data
- Email security to prevent phishing-based data breaches
- Access controls and multi-factor authentication
- Encrypted backups with tested recovery procedures
- Incident detection and response capability
The Breach Notification Problem
Under GDPR, a personal data breach must be reported to the supervisory authority within 72 hours of becoming aware of it.
That timeline is nearly impossible without active monitoring. If you do not have 24/7 security monitoring, you likely will not become aware of a breach until days or weeks after it occurs — by which time you are already in violation.
A managed SOC solves this by detecting breaches as they happen and notifying you immediately.
How CyberOM Addresses Article 32
| Article 32 Requirement | CyberOM Service | |---|---| | Encryption | Acronis EDR + Backup | | Availability and resilience | Backup & Disaster Recovery | | Ability to restore | Disaster Recovery | | Regular testing | Monthly security reporting | | Incident detection | SOC 24/7 + MDR |
Ready to protect your business?
See how CyberOM's managed cybersecurity packages keep you covered 24/7.
