Security
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Technical and organizational measures to protect personal data
Overview
21 sources · Jul 15, 2026Legal Framework
Security obligations under the GDPR are anchored in Article 32, which mandates that controllers and processors implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures must protect against unauthorized or unlawful processing and against accidental loss, destruction, or damage. Article 25 reinforces this through data protection by design and by default, requiring that security be built into processing systems from the outset. Article 5(1)(f) establishes integrity and confidentiality as a core principle, meaning personal data must be processed in a manner ensuring appropriate security. Recital 29 specifically incentivizes pseudonymization as a security-enhancing measure, encouraging controllers to separate additional identifying information from the processed data. The constitutional underpinning derives from Article 8 ECHR and Article 7 of the EU Charter of Fundamental Rights, which require that any interference with private life through data processing be accompanied by sufficient safeguards.
Key Developments
The CJEU's ruling in Digital Rights Ireland established a critical baseline: technical and organizational measures must be specific and adapted to the volume, sensitivity, and risk profile of the data involved. The Court struck down the Data Retention Directive partly because its security provisions were insufficiently tailored — they permitted economic considerations to dilute the required level of protection and failed to ensure irreversible destruction of data at the end of retention periods. This sets a clear precedent: cost considerations cannot serve as the primary determinant of security standards when sensitive or large-scale data is at stake.
Enforcement actions confirm that DPAs apply these principles rigorously. The Romanian ANSPDCP fined Poșta Română €5,000 for insufficient technical measures, while the Polish UODO imposed a €23,540 fine on the Minister of Justice for inadequate technical and organizational safeguards. Both decisions signal that public-sector entities face scrutiny equal to private operators. The EDPB's Guidelines 4/2019 on Article 25 further clarify that data protection by design is not optional architecture — it is a binding obligation requiring demonstrable, documented decisions about security configurations from the earliest stages of system development.
Practical Guidance
Conduct and document risk assessments tied to Article 32, evaluating the risks of varying likelihood and severity for the rights and freedoms of data subjects. The level of encryption, access controls, and logging must correspond to identified risks, not to budgetary convenience.
Implement pseudonymization where feasible, as explicitly encouraged by Recital 29. Separate the additional information needed to re-identify individuals and restrict access to it under strict controls.
Embed security into system design from inception under Article 25. The EDPB Guidelines 4/2019 require demonstrable evidence that privacy-protective defaults and security features were selected during development, not retrofitted.
Establish data retention and destruction protocols that ensure irreversible deletion at the end of the retention period. Digital Rights Ireland makes clear that failure to guarantee irreversible destruction renders security measures deficient per se.
Review and update measures continuously. Article 32 requires ongoing evaluation. Static security configurations that are not reassessed against evolving threats constitute non-compliance, as reflected in the UODO enforcement against the Polish Minister of Justice.