Encryption
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Encryption and cryptographic measures
Overview
19 sources · Jul 23, 2026Legal Framework
Article 32 GDPR establishes the core obligation: controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing. Encryption is explicitly enumerated as an example of such a measure, alongside pseudonymisation. The provision requires a contextual assessment — state of the art, implementation costs, nature and scope of processing, and risk to data subjects all factor into determining what is "appropriate."
The AI Act reinforces this framework. Recital 69 makes clear that privacy and data protection must be guaranteed throughout the entire AI system lifecycle. Providers must apply data minimisation and data protection by design and by default. Encryption is expressly identified as a measure that can satisfy these principles, alongside anonymisation and technologies that permit algorithms to be brought to the data rather than transmitting personal data between parties.
The DSA touches encryption only obliquely, in the context of intermediary services and liability exemptions — but signals that deliberately facilitating illegal activity through encrypted communications can strip a provider of its neutral intermediary status.
Key Developments
Dutch courts have grappled extensively with encrypted communication platforms in criminal proceedings. The EncroChat and SkyECC cases established that evidence derived from encrypted PGP phones is admissible, but courts have demanded caution — the Rechtbank noted that many messages were only unilaterally decrypted and that an unknown number of chats are missing. The standard set is one of evidentiary restraint: encrypted data must be treated with care when its completeness cannot be verified.
The Amsterdam Court of Appeal's ruling on licence plate parking confirmed that data collection through technical systems is not inherently incompatible with the ECHR or data protection law, provided the processing meets proportionality requirements — a principle that extends to encrypted data collection and retention.
Enforcement actions confirm that the absence of encryption triggers liability. The Slovenian DPA fined a controller €1,300 after an employee stored personal data on a work laptop without security measures. The Spanish AEPD fined FREE TECHNOLOGIES EXCOM €10,000 following a password reset process that failed to safeguard personal data. Both decisions underscore that Article 32's encryption expectation is not aspirational — failure to encrypt personal data on portable devices or in transit constitutes a concrete violation.
Practical Guidance
Conduct a risk-based encryption assessment under Article 32 GDPR. Document the state of the art, implementation costs, and the specific risks to data subjects. This assessment must justify the chosen encryption standard or explain why encryption was deemed unnecessary for a particular processing context.
Encrypt personal data at rest on all portable devices and endpoints. The Slovenian enforcement action confirms that unencrypted personal data on work laptops is a direct Article 32 violation, regardless of whether a breach actually occurred.
Apply encryption as a data protection by design measure in AI systems. Recital 69 of the AI Act positions encryption as a core component of privacy-by-design compliance for AI providers, particularly where training data involves personal data.
Preserve evidentiary integrity when handling encrypted data. Following the EncroChat and SkyECC jurisprudence, organisations that decrypt or process encrypted communications must document the completeness and reliability of decrypted data, acknowledging gaps and limitations.
Secure password and key management processes. The Spanish AEPD decision demonstrates that encryption is undermined by weak credential handling — password resets and key management must themselves meet Article 32 security standards.