Encryption
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Encryption and cryptographic measures
Overview
23 sources · Aug 27, 2026Legal Framework
Encryption occupies a central role in the GDPR's security architecture. Article 32(1)(a) lists it among the measures controllers and processors must consider when implementing security appropriate to risk, alongside pseudonymisation. The provision is not prescriptive—encryption is flagged as one option among "appropriate technical and organisational measures"—but its prominence signals that regulators and courts treat it as a baseline expectation for certain data categories and risk profiles.
Encryption also functions as a breach-notification safe harbour. Under Article 34(3)(a), a controller is excused from notifying data subjects of a high-risk breach when protective measures were applied to the affected data—specifically:
"those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption"
— GDPR Art. 34(3)(a)
The CJEU in VB v Natsionalna agentsia za prihodite confirmed that Article 32 requires a contextual, risk-based assessment of security measures, weighing state of the art, implementation costs, and the nature of processing. Encryption is therefore neither categorically mandatory nor sufficient in isolation; its adequacy depends on the surrounding risk picture.
Key Developments
Swedish DPA enforcement against Region Sörmland, Region Värmland, Region Stockholm, and MedHelp AB illustrates the practical consequences of failing to encrypt. In each case, call recordings were exposed because a network-attached storage device was publicly accessible and:
"did not use encrypted communications"
— IMY, Region Sörmland decision
These decisions confirm that the absence of encryption on internet-facing systems storing personal data will be treated as a failure to meet Article 32's appropriateness standard.
The EDPB's breach-notification guidelines add nuance: encrypted data that is exfiltrated still constitutes a personal data breach requiring notification to the supervisory authority, but notification to data subjects may be unnecessary if the encryption key remains secure. The critical threshold is key integrity:
"if the confidentiality of the key is intact – i.e., the key was not compromised in any security breach, and was generated so that it cannot be ascertained by available technical means by any person who is not authorised to access it – then the data are in principle unintelligible"
— EDPB Guidelines 9/2022 §76
Conversely, the EDPB warns that loss of a decryption key can itself constitute an availability breach under Article 32, since the controller permanently loses access to the data.
Status of the Debate
The core principle—that encryption is a recognised, risk-calibrated security measure under Article 32 and a potential exemption under Article 34—is settled. What remains contested is the threshold question: when is the absence of encryption per se unlawful? Courts have not yet drawn a bright line. The CJEU's VB ruling emphasises judicial deference to the controller's risk assessment, but DPAs in Sweden treated unencrypted internet-facing storage as categorically deficient. Resolution will likely come from further CJEU guidance on whether Article 32 permits a contextual defence where encryption is absent but other measures mitigate risk.
Practical Guidance
- Encrypt data at rest on internet-facing or shared infrastructure. The Swedish enforcement actions show that unencrypted storage accessible over the internet will be treated as non-compliant with Article 32, regardless of other mitigations.
- Protect encryption keys independently from encrypted data. Article 34(3)(a) relief depends on key confidentiality; if the key is compromised, the breach notification exemption falls away and data-subject notification becomes mandatory.
- Document the risk assessment behind encryption decisions. Article 32 requires weighing state of the art, costs, and risk profile—controllers should record why encryption was or was not implemented for each processing activity.
- Treat key loss as a potential availability breach. Losing a decryption key without backup may trigger Article 33 notification obligations, as the EDPB classifies this as a loss of availability.
- Layer encryption with other measures. Encryption alone does not satisfy Article 32; combine it with access controls, regular testing under Article 32(1)(d), and incident-response readiness.
why this is here
the role of encryption in protecting human rights online
Directly mentions encryption but only as one of three examined areas, without elaboration on cryptographic measures.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 43 Guidance · all 81 Enforcement · all 33 News