Security of processing
Summary
Controllers and processors must implement technical and organisational measures appropriate to the risk (pseudonymisation, encryption, resilience, ability to restore availability, regular testing), taking into account state of the art and cost.
Read the full official text: https://gdpr-info.eu/art-32-gdpr/
← Article 30
Records of processing activities
Article 33 →
Notification of a personal data breach to the supervisory authority
Track GDPR article 32 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial