Skip to content
+370 5 212 1506 info@dat.lt

GDPR security measures: what Article 32 actually requires

24 September 2026 · Good to know

The GDPR sets no mandatory list of security measures. It requires the controller and the processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32(1) GDPR). What is appropriate depends on the risk: what data, how much of it, how it is processed and what would happen to people if it leaked or was lost. On top of that, the controller must be able to demonstrate compliance (Article 5(2) GDPR).

In practice this means two things. First, a risk assessment must be carried out, and it is worth writing it down, because otherwise you cannot prove it. Second, measures matched to those risks must be in place, and that too must be provable. Here we cover what the law actually says, how courts and the supervisory authority judge whether measures were appropriate, and what you face when they are missing.

What the law requires

The starting point is the integrity and confidentiality principle. Data must be processed in a way that ensures appropriate security, including protection against unauthorised processing and against accidental loss, destruction or damage (Article 5(1)(f) GDPR).

Article 32(1) GDPR sets what to take into account when choosing measures: the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the likelihood and severity of the risk to people’s rights. It then gives examples, which apply “as appropriate”:

  • pseudonymisation and encryption;
  • the ability to ensure the ongoing confidentiality, integrity, availability and resilience of systems;
  • the ability to restore data in a timely manner after a physical or technical incident;
  • regular testing of the measures and assessment of their effectiveness.

When assessing risk, the focus is on what can happen to the data: destruction, loss, alteration, unauthorised disclosure or unauthorised access (Article 32(2) GDPR).

Two duties are often forgotten. First, any employee or other person acting under the controller’s authority who has access to the data may process it only on the controller’s instructions, unless the law requires them to do so (Article 32(4) GDPR). This is where access rights by role come from: whoever has no work with the data has no access to it. Second, by default only the data necessary for the purpose may be processed, and without a person’s intervention the data must not be accessible to an indefinite number of people (Article 25(2) GDPR).

Measures are not a one-off job. They must be reviewed and updated where necessary (Article 24(1) GDPR). The duty applies to the processor too: Article 32 binds it directly. And the controller may use only processors that provide sufficient guarantees of appropriate measures (Article 28(1) GDPR). When a data processing agreement is required is covered in Data processing agreement: when required and the risk without one.

Example: does any law set out specific measures?

A client asked whether data protection law says anything more specific about technical security measures than a general duty to keep data safe.

Our answer: the GDPR sets no specific list of measures; it sets an outcome. More specific requirements exist for certain sectors. For example, public electronic communications service providers must ensure that only authorised employees with that right can access personal data, that data is protected against destruction, loss and unlawful disclosure, and that a personal data security policy is in place (Article 74(1) ERĮ). Some other sectors also have more specific rules. The GDPR requirement applies to everyone, these sectors included. So you need to (a) carry out a risk assessment and document it, and (b) put in place measures that match the risks and have a description of them. Recognised information security standards can serve as a reference point. Certification is not mandatory, but a recognised certificate makes due care easier to show.

This does not mean anything goes. The controller must be able to demonstrate that the chosen measures are sufficient (Article 5(2) GDPR), and in a claim for damages that burden is on it (C-340/21).

How appropriateness is judged

The key ruling is the Court of Justice judgment of 14 December 2023 in Case C-340/21. The case arose after a cyberattack on a state authority’s information system, when the data of more than six million people was published online. The Court held:

  • the mere fact that third parties disclosed data without authorisation or gained unauthorised access to it does not mean the measures were not appropriate;
  • a court assesses appropriateness in concrete terms: whether the nature, content and implementation of the measures were adapted to the risks of that particular processing;
  • in claims for damages, it is the controller who must prove that the measures were appropriate;
  • a court-appointed expert’s report is not always a necessary and sufficient means of proof;
  • the controller is not released from liability simply because the damage was caused by hackers – it must prove that it is in no way responsible for the event;
  • a person’s fear that their leaked data may be misused can in itself be non-material damage.

When deciding whether to impose a fine and how much, the supervisory authority takes into account the degree of responsibility of the controller or processor, considering the measures they implemented under Articles 25 and 32 (Article 83(2)(d) GDPR). It can order them to provide any information it needs for its tasks (Article 58(1)(a) GDPR). So after an incident you need something to show: the risk assessment, the description of measures, the access rights procedure and the breach log. Documenting all breaches, including those not notified, is mandatory (Article 33(5) GDPR).

What most often fails

Typical gaps that make it hard for measures to survive a review:

  • a description of measures exists but does not match what actually happens;
  • measures were chosen without a risk assessment, so nobody can explain why these ones;
  • shared logins and broad administrator rights granted for convenience;
  • backups are made, but restoring from them has never been tested;
  • personal data is sent by email with no protection, and a wrong recipient is treated as a trifle;
  • nobody has checked how service providers secure the data.

Several consequences can arrive at once. A breach of Article 32 falls among the obligations in Articles 25 to 39, for which the fine can reach up to ten million euros or, for an undertaking, up to 2% of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)(a) GDPR). If the integrity and confidentiality principle itself is breached, the stricter band applies – up to twenty million euros or, for an undertaking, up to 4% of turnover, whichever is higher (Article 83(5)(a) GDPR). Lower caps apply to Lithuanian public authorities and bodies. For breaches of Article 83(4), up to 0.5 per cent of the current year’s budget and other total annual income received in the previous year, but no more than thirty thousand euros (Article 33(1) ADTAĮ). For breaches of Article 83(5), including breaches of the principles, up to 1 per cent, but no more than sixty thousand euros (Article 33(2) ADTAĮ). A body that carries on commercial activity faces the ordinary GDPR fines (Article 33(3) ADTAĮ). More in our article on fines for public institutions.

Besides a fine, any person who has suffered material or non-material damage can claim compensation (Article 82(1) GDPR). In Case C-683/21 the Court of Justice held that a fine can be imposed only where it is established that the infringement was intentional or negligent. But negligence is established where the controller could not have been unaware that its conduct was unlawful (C-683/21, para 81). With no risk assessment and no description of measures, that is easy to show.

One piece of good news: if appropriate measures that make the data unintelligible to an outsider, such as encryption, were applied to the affected data, people do not have to be notified of the breach (Article 34(3)(a) GDPR). Whether VDAI must be notified is assessed separately. How to act after an incident is covered in our article on personal data breaches.

When to call a lawyer

  • when an incident has happened and you need to know whether your measures would stand up to a review;
  • when you receive a VDAI inquiry or a person’s claim about leaked data;
  • when you process health, financial, children’s or other sensitive data on a large scale;
  • when a customer or partner demands proof of your security measures in a contract or questionnaire;
  • when you have no risk assessment and no description of measures, or they have not been updated for years.

Frequently asked questions

Is ISO 27001 certification mandatory?

No. The GDPR does not require any particular standard. An approved code of conduct or an approved certification mechanism under the GDPR can be one element in demonstrating compliance with Article 32(1) (Article 32(3) GDPR). A general information security certificate helps show due care, but on its own it does not prove that personal data specifically is protected in line with its risk.

Is encryption mandatory?

Not always, because Article 32(1) GDPR lists encryption as a measure that applies “as appropriate”. But where data is sensitive, carried around or sent, its absence is hard to explain. Encryption also has a clear legal benefit: if properly encrypted data leaks and the key has not been compromised, people do not have to be notified (Article 34(3)(a) GDPR). Whether VDAI must be notified is assessed separately.

If our system was hacked, does that mean we breached the GDPR?

Not by itself. In Case C-340/21 the Court of Justice held that unauthorised access by third parties alone does not mean the measures were not appropriate. But in a claim for damages it is you, not the person harmed, who will have to prove that the measures were appropriate and adapted to the risk.

Does the security duty also apply to our service providers?

Yes. Article 32(1) GDPR applies directly to the processor as well. But the controller remains responsible for which processor it chose: it may use only those that provide sufficient guarantees of appropriate measures (Article 28(1) GDPR). So it is worth checking a service provider’s security before signing, not after an incident.

How to start

Send us your existing risk assessment, description of security measures and breach log, if you have them. If you do not, we will start with a conversation about what data you process and in which systems. We will tell you which gaps are the most serious and what needs documenting first.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and consultations.

Get a free assessment

Related articles