Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Back to the act

EU regulatory register · GDPR

Article 32Security of processing

CELEX 32016R0679 · Read on 2026-08-18 · Chapter IV

Official text

Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.

1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:

(a)

the pseudonymisation and encryption of personal data;

(b)

the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

(c)

the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;

(d)

a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

2. In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.

3. Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of this Article.

4. The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by Union or Member State law.

Open the article on EUR-Lex

Other articles in this chapter

Related articles

Articles in other acts connected to this one, with the reason written against the text. The map is a route between acts, not an assessment.

  • Analogous to · mutualDORA · 9

    Safeguards for processing meet safeguards for the ICT systems of a financial entity: the same kind of requirement, a different object of protection.

    CELEX 32022R2554 · 2026-08-18

  • Analogous to · mutualNIS2 · 21

    Both articles require security measures proportionate to the risk, one for personal data and one for network and information systems.

    CELEX 32022L2555 · 2026-08-18

Judgments of the Court of Justice

3 decisions

  • C-169/23Court of Justice of the European Union

    Nemzeti Adatvédelmi és Információszabadság Hatóság v UC

    Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation to provide information – Article 14(5)(c) – Data generated by the controller in the context of its own processes – Right to complain – Competence of the supervisory authority – Article 77(1) – Appropriate measures to protect the data subject’s legitimate interests provided for by the Member State law to which the controller is subject – Measures relating to the security of data processing – Article 32.

  • C-687/21Court of Justice of the European Union

    BL v MediaMarktSaturn Hagen-Iserlohn GmbH

    Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Interpretation of Articles 5, 24, 32 and 82 – Assessment of the validity of Article 82 – Inadmissibility of the request for an assessment of validity – Right to compensation for damage caused by data processing which infringes that regulation – Transmission of data to an unauthorised third party on account of an error made by the employees of the controller – Assessment of the appropriateness of the protection measures implemented by the controller – Compensatory function fulfilled by the right to compensation – Effect of the severity of the infringement – Whether necessary to establish the existence of damage caused by that infringement – Concept of ‘non-material damage’.

  • C-340/21Court of Justice of the European Union

    VB v Natsionalna agentsia za prihodite

    Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to that processing – Article 24 – Accountability of the controller – Article 32 – Measures implemented to ensure security of processing – Assessment of the appropriateness of such measures – Scope of judicial review – Taking of evidence – Article 82 – Right to compensation and liability – Possible exemption from liability of the controller in the event of infringement by third parties – Claim for compensation for non-material damage based on fear of potential misuse of personal data.

The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit