Skip to content
Topic Contested in court

Security

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Technical and organizational measures to protect personal data

1,409 linked items 20 Laws93 Case Law110 Guidance1013 Enforcement122 News

Overview

21 sources · Jul 15, 2026

Legal Framework

Security obligations under the GDPR are anchored in Article 32, which mandates that controllers and processors implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures must protect against unauthorized or unlawful processing and against accidental loss, destruction, or damage. Article 25 reinforces this through data protection by design and by default, requiring that security be built into processing systems from the outset. Article 5(1)(f) establishes integrity and confidentiality as a core principle, meaning personal data must be processed in a manner ensuring appropriate security. Recital 29 specifically incentivizes pseudonymization as a security-enhancing measure, encouraging controllers to separate additional identifying information from the processed data. The constitutional underpinning derives from Article 8 ECHR and Article 7 of the EU Charter of Fundamental Rights, which require that any interference with private life through data processing be accompanied by sufficient safeguards.

Key Developments

The CJEU's ruling in Digital Rights Ireland established a critical baseline: technical and organizational measures must be specific and adapted to the volume, sensitivity, and risk profile of the data involved. The Court struck down the Data Retention Directive partly because its security provisions were insufficiently tailored — they permitted economic considerations to dilute the required level of protection and failed to ensure irreversible destruction of data at the end of retention periods. This sets a clear precedent: cost considerations cannot serve as the primary determinant of security standards when sensitive or large-scale data is at stake.

Enforcement actions confirm that DPAs apply these principles rigorously. The Romanian ANSPDCP fined Poșta Română €5,000 for insufficient technical measures, while the Polish UODO imposed a €23,540 fine on the Minister of Justice for inadequate technical and organizational safeguards. Both decisions signal that public-sector entities face scrutiny equal to private operators. The EDPB's Guidelines 4/2019 on Article 25 further clarify that data protection by design is not optional architecture — it is a binding obligation requiring demonstrable, documented decisions about security configurations from the earliest stages of system development.

Practical Guidance

  • Conduct and document risk assessments tied to Article 32, evaluating the risks of varying likelihood and severity for the rights and freedoms of data subjects. The level of encryption, access controls, and logging must correspond to identified risks, not to budgetary convenience.

  • Implement pseudonymization where feasible, as explicitly encouraged by Recital 29. Separate the additional information needed to re-identify individuals and restrict access to it under strict controls.

  • Embed security into system design from inception under Article 25. The EDPB Guidelines 4/2019 require demonstrable evidence that privacy-protective defaults and security features were selected during development, not retrofitted.

  • Establish data retention and destruction protocols that ensure irreversible deletion at the end of the retention period. Digital Rights Ireland makes clear that failure to guarantee irreversible destruction renders security measures deficient per se.

  • Review and update measures continuously. Article 32 requires ongoing evaluation. Static security configurations that are not reassessed against evolving threats constitute non-compliance, as reflected in the UODO enforcement against the Polish Minister of Justice.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Guidance EDPB Oct 2020 Security as a data protection principle
why this is here
technical and organisational measures which are designed to implement the data protection principles

Security measures are part of data protection principles, but the document focuses on design and default, not just security.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Security and privacy considerations
why this is here
security and privacy of connected vehicles

The document acknowledges security as a related topic but does not provide detailed security measures.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 07/2022 certification as a tool for transfers Guidelines on certification and identifying certification criteria Guidelines ·EDPB Guidance EDPB Feb 2023 Technical and organizational measures
why this is here
technical and organisational measures guaranteeing protection (Annex 2, Section 10.q)

The certification criteria reference technical and organizational measures, which are part of data security under Article 32 GDPR.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 06/2020 interplay of the Second Payment Services Directive and the GDPR Guidelines on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Guidelines ·EDPB Guidance EDPB Dec 2020 Security measures mention
why this is here
the relevant security requirements laid down in the GDPR must be implemented

The document recites the need to comply with GDPR security requirements in the context of PSD2, but does not detail specific security measures.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

art 10 Processing of personal data relating to criminal convictions and offences Laws GDPR Apr 2016 Safeguards for rights and freedoms
why this is here
processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects

The provision mentions safeguards but not technical/organisational security measures; it is about legal safeguards rather than data security practices.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Guidance EDPB Jul 2021 Security measures mentioned for processors
why this is here
Elements to be taken into account could be the processor’s expert knowledge (e.g. technical expertise with regard to security measures and data breaches)

Security is referenced only in the context of processor selection criteria, not as a central principle.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 2/2023 Technical Scope of Art. 5(3) of ePrivacy Directive Guidelines ·EDPB Guidance EDPB Oct 2024 protection of terminal equipment
why this is here
the goal of that provision is to protect the users’ terminal equipment, as they are part of the private sphere of the users

Discusses integrity and confidentiality of terminal equipment, which relates to security but not central security measures.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 93 Case Law · all 110 Guidance · all 1013 Enforcement · all 50 Literature · all 122 News