Skip to main content
Praxikon

Article 32: Security of processingAI-relevant

Praxikon tracks Article 32 (Security of processing) under the GDPR, alongside the EU AI Act, citing the source for every statement.

Chapter IVIn force since 25-05-2018

What does Article 32 govern?

Article 32 requires both the controller and the processor to secure personal data appropriately. What is appropriate depends on the state of the art, the costs, the nature and scope of the processing and the risks to the people concerned (paragraph 1). The article gives examples of measures: pseudonymisation and encryption, ensuring the ongoing confidentiality, integrity, availability and resilience of systems, timely restoration after an incident and regular testing of the measures (paragraph 1(a) to (d)). In deciding the level of security you look in particular at the risks of destruction, loss, alteration, unauthorised disclosure or unauthorised access (paragraph 2); recital 83 explains that such incidents can lead to physical, material or non-material damage to people. Anyone acting under the authority of the organisation with access to personal data may process them only on instructions from the controller (paragraph 4); if something goes wrong despite these measures, Articles 33 and 34 set out what you must report.

Key term: Risk-based security: the level of security must match the likelihood and severity of the risks to the people concerned (paragraphs 1 and 2)

Directly affects:controllerprocessor

Praxikon’s reading of the text and the recitals; the official text below prevails.

AI Act intersection

Security of processing overlaps with AI Act cybersecurity requirements (Art. 15(4) and (5)).

Official text

/
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (a) the pseudonymisation and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.
Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of this Article.
The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by Union or Member State law.

Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.

What does this mean for you?

Controller

Assess for each processing activity what the risks are for the data subjects and record which technical and organisational measures fit those risks (paragraphs 1 and 2). Think of encryption, pseudonymisation, backups that make restoration possible and a fixed rhythm of testing (paragraph 1(a) to (d)). Make sure that staff, including for example staff who enter personal data into an AI tool, process those data only on your instructions (paragraph 4).

Processor

The same security obligation rests directly on you, not only through the contract with the controller (paragraph 1). Assess the risks of the processing you carry out (paragraph 2) and make sure your staff with access to personal data act only on instructions from the controller (paragraph 4).

Compliance checklist

Related recitals

Cross-references

Frequently asked questions

Connections

What connects to Article 32 GDPR

Themes where this returns

The counterpart in the other law

Case law

Guidelines

Enforcement and fines