UK & EU · Regulation (EU) 2016/679, Article 32

GDPR Article 32 — security of processing

Article 32 requires controllers and processors to implement technical and organisational measures appropriate to the risk. It is deliberately risk-based rather than prescriptive: the four measures it names in 32(1)(a) to (d) are examples of what may be appropriate, not a checklist that can be completed. The UK GDPR carries a materially identical Article 32.

Scope

Does this apply to you?

Article 32 has no company-size threshold. If you process personal data, it binds you — and almost every business processes personal data, because staff and customer contact details are personal data.

You are likely in scope if

  • You process personal data as a controller or as a processor. Article 32 binds both, and Article 28(3)(c) pushes the same obligation down into processor contracts.
  • You are established in the EU, or you offer goods or services to people in the EU, or you monitor their behaviour there (Article 3). For the UK, the UK GDPR applies the same duty.
  • You are a small company. The 250-employee exemption people remember is in Article 30, on records of processing activities. It is not in Article 32 and does not reduce this duty.

You are probably not in scope if

  • You process no personal data whatsoever. In practice this is close to nonexistent for an operating business.
  • The processing is purely personal or household activity, which Article 2(2)(c) excludes from the Regulation.

What counts as “appropriate” under Article 32 depends on the state of the art, the cost of implementation, and the risk to the people whose data you hold. That is a judgement about your specific processing. Neither this page nor Fortoxa makes it for you, and no measure listed here is guaranteed to be sufficient for your circumstances.

Requirements

What the framework asks for.

Named as the framework names them, with its own references, so you can check this page against the source below.

  • 32(1)(a)

    Pseudonymisation and encryption of personal data

    Named as an example measure. Whether either is appropriate — and where in your systems it applies — follows from your risk assessment rather than from the article.

  • 32(1)(b)

    Ongoing confidentiality, integrity, availability and resilience of processing systems and services

    A continuing property of the systems that process personal data, not a one-time configuration.

  • 32(1)(c)

    Ability to restore availability and access in a timely manner after a physical or technical incident

    In practice: backups that exist, and restores that have been tested and shown to work.

  • 32(1)(d)

    A process for regularly testing, assessing and evaluating effectiveness

    The article asks for a repeating process with a record, not an annual point-in-time exercise.

  • 32(2)

    Risk assessment

    In assessing appropriate security, account must be taken of the risks from accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data.

The register

What Fortoxa puts against each requirement.

Fortoxa evidences transport encryption, access and detection history, and the record of control checks. It does not evidence restoration, and 32(1)(c) is shown as not supported rather than quietly omitted.

GDPR Article 32 — security of processing — control register

3 of 5 evidenced

  • 32(1)(a)

    Pseudonymisation and encryption of personal data

    Transport encryption state for monitored services

    fortoxa-agent · 18 min ago

    Live
  • 32(1)(b)

    Ongoing confidentiality, integrity, availability and resilience

    Access records and detection history over the retention window

    log_events · 1 min ago

    Live
  • 32(1)(c)

    Ability to restore availability and access in a timely manner

    Recovery evidence — held by you, referenced from the register but not produced by it

    not collected by Fortoxa · never collected

    Not supported yet
  • 32(1)(d)

    Regular testing, assessing and evaluating effectiveness

    Dated record of each control check and its result

    security-score-service · 9 min ago

    Calculated
  • 32(2)

    Risk assessment informing the measures

    Your assessment of risk to data subjects is an input to Fortoxa, not an output of it

    not collected by Fortoxa · never collected

    Not configured

Rows marked as not measured are shown, not hidden. A register with every requirement satisfied is the outcome this product exists to prevent.

Example workspace, sample data. Your own register is built from your servers once an agent is installed.

Not covered

What stays your job.

Fortoxa evidences what it can observe on the servers you install the agent on. Everything below is outside that, and the register marks it as not measured rather than as a pass.

  • The risk assessment

    Article 32 is proportionate by construction: the measures must match the risk to the people whose data you hold. Deciding what that risk is, and therefore what is appropriate, is yours and cannot be delegated to a monitoring tool.

  • Pseudonymisation

    Whether personal data is pseudonymised is a decision inside your own application design and data model. Fortoxa observes transport encryption on monitored services; it does not see what you store or how.

  • Restoration — 32(1)(c)

    Backups, and restore tests that prove they work. Fortoxa does not run, hold, or verify your backups, so this requirement is marked not supported in the register rather than assumed.

  • Breach notification

    Article 33 gives 72 hours to notify the supervisory authority once aware of a personal data breach, and Article 34 covers telling the individuals. Fortoxa’s incident timeline is evidence you can attach to such a notification. Deciding whether one is required, and making it, is yours.

  • Records of processing — Article 30

    A separate article with a separate obligation and its own partial exemption. Fortoxa does not produce an Article 30 record.

  • Organisational measures

    Article 32 says technical *and organisational*. Policies, training, confidentiality undertakings and the Article 32(4) duty to ensure staff act only on instructions are organisational, and sit outside what an agent on a server can observe.

Sources

Check this page against the text.

Everything above is Fortoxa's reading of the framework. It is not the framework, and it is not advice about your obligations. The publishers below are authoritative; this page is not.

Next

See what your own servers produce.

Install the agent on one server and the register builds itself from what it finds — including the requirements it cannot see.

The control register and the evidence export are Business features, £349/month. Monitoring, alerts and the live activity feed start at £29 on Micro, which does not include the register. Starter and Business include a 14-day trial on a new subscription.