Article 32: Security of processingAI-relevant
Praxikon tracks Article 32 (Security of processing) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 32 govern?
Article 32 requires both the controller and the processor to secure personal data appropriately. What is appropriate depends on the state of the art, the costs, the nature and scope of the processing and the risks to the people concerned (paragraph 1). The article gives examples of measures: pseudonymisation and encryption, ensuring the ongoing confidentiality, integrity, availability and resilience of systems, timely restoration after an incident and regular testing of the measures (paragraph 1(a) to (d)). In deciding the level of security you look in particular at the risks of destruction, loss, alteration, unauthorised disclosure or unauthorised access (paragraph 2); recital 83 explains that such incidents can lead to physical, material or non-material damage to people. Anyone acting under the authority of the organisation with access to personal data may process them only on instructions from the controller (paragraph 4); if something goes wrong despite these measures, Articles 33 and 34 set out what you must report.
Key term: Risk-based security: the level of security must match the likelihood and severity of the risks to the people concerned (paragraphs 1 and 2)
Directly affects:controllerprocessor
Praxikon’s reading of the text and the recitals; the official text below prevails.
AI Act intersection
Security of processing overlaps with AI Act cybersecurity requirements (Art. 15(4) and (5)).
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
Assess for each processing activity what the risks are for the data subjects and record which technical and organisational measures fit those risks (paragraphs 1 and 2). Think of encryption, pseudonymisation, backups that make restoration possible and a fixed rhythm of testing (paragraph 1(a) to (d)). Make sure that staff, including for example staff who enter personal data into an AI tool, process those data only on your instructions (paragraph 4).
Processor
The same security obligation rests directly on you, not only through the contract with the controller (paragraph 1). Assess the risks of the processing you carry out (paragraph 2) and make sure your staff with access to personal data act only on instructions from the controller (paragraph 4).
Compliance checklist
Related recitals
Cross-references
Frequently asked questions
Connections
What connects to Article 32 GDPR
Themes where this returns
The counterpart in the other law
Case law
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Russmedia: an online marketplace operator is controller for personal data in adverts and must check before publication
2025-12-02 · final, Hof van Justitie van de EU (Grote kamer), X tegen Russmedia Digital SRL en Inform Media Press SRL
Guidelines
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
2021-12-14 · final, European Data Protection Board (EDPB)
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
2020-10-20 · final, European Data Protection Board (EDPB)
- Guidelines 01/2025 on Pseudonymisation
2025-01-16 · adopted, European Data Protection Board (EDPB)
Enforcement and fines
- HAN University of Applied Sciences fined 175,000 euros for inadequate security
2025-12-15 · final, Autoriteit Persoonsgegevens