Skip to main content
Compliance · GDPR

Article 32(1)(d) asks for a process for regularly testing effectiveness

The Official Journal text reads: “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.” It is a process, the measures are technical and organisational, and the yardstick Article 32(2) supplies is risk to the personal data. This page starts where the question usually starts — which part of an engagement answers which part of that sentence.

The three verbs

Testing, assessing, evaluating — and what each one leaves behind

The clause names three things in sequence. An engagement produces a different artefact against each, and the third is the one a controller asks to see.

01 First verb

Testing

In the clause
The first of the three things the process is for. Article 32(1)(d) names the activity, and the chapeau of Article 32(1) sets the terms on which the controller and the processor settle how it is carried out.
In the engagement
B-52 runs the coverage classes you authorise against the scope you sign off. Every finding it reports carries the request that produced it and the response that came back, with the proving portion marked.
In the record
Steps written to be re-run by your own engineers rather than read by them. The artefact is the test, not a statement that testing occurred.
02 Second verb

Assessing

In the clause
Article 32(2) supplies the yardstick: account shall be taken in particular of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
In the engagement
Each finding carries a CVSS v4.0 severity with the vector printed, plus the CWE. A CVSS vector is a technical severity and the yardstick above is risk to the personal data, which are two different measurements.
In the record
The vector is printed so your DPO can rebase it against the processing the finding actually touches, rather than inherit a number computed without that context.
03 Third verb

Evaluating effectiveness

In the clause
The object of the sentence is the effectiveness of technical and organisational measures. The duty attaches to a process, and a process is a thing that runs.
In the engagement
Findings carry through open, fixed, retested and closed. A finding closes on a retest that cannot reproduce it, and one that still reproduces returns to open.
In the record
A record of whether the measure worked after it was changed — which is the question the word “effectiveness” asks, and the one a remediation ticket on its own cannot answer.

Point by point

What a finding reported against each point of Article 32(1) looks like

The chapeau introduces the four points with the words “including inter alia as appropriate”, and that phrase governs every one of them — each is calibrated to the risk of your own processing.

Article 32(1)What an engagement reports against it
(a) the pseudonymisation and encryption of personal data Paths where personal data moves or rests without the protection the design says it has: transport, storage, backup, export and log paths the testing reaches inside the authorised scope, each reported with the exchange that demonstrated it.
OJ L 119, 4.5.2016, p. 51. Read 2026-09-14. Governed by the chapeau’s “including inter alia as appropriate”.
(b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services Authentication, authorisation, session and tenancy findings — anything that lets one party reach another party’s records, or a role reach data its own permissions do not cover. They are reported under this point because the ability it names is the one they defeat.
OJ L 119, 4.5.2016, p. 51–52. Read 2026-09-14.
(c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident Destructive and state-changing actions sit behind the first of three approval gates, so what an engagement produces here is the conditions under which availability could be affected, evidenced, rather than a demonstration produced by causing the incident.
OJ L 119, 4.5.2016, p. 52. Read 2026-09-14. The gate applies on every class and in all three delivery models.
(d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing The engagement itself, and the record it leaves: scope and authorisation, the artefact behind each finding, the severity with its vector, and the state each finding reached. This is the point the rest of this page is about.
OJ L 119, 4.5.2016, p. 52. Read 2026-09-14, in the Publications Office file of the signed Official Journal.

(a) the pseudonymisation and encryption of personal data

What an engagement reports against it
Paths where personal data moves or rests without the protection the design says it has: transport, storage, backup, export and log paths the testing reaches inside the authorised scope, each reported with the exchange that demonstrated it.

OJ L 119, 4.5.2016, p. 51. Read 2026-09-14. Governed by the chapeau’s “including inter alia as appropriate”.

(b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services

What an engagement reports against it
Authentication, authorisation, session and tenancy findings — anything that lets one party reach another party’s records, or a role reach data its own permissions do not cover. They are reported under this point because the ability it names is the one they defeat.

OJ L 119, 4.5.2016, p. 51–52. Read 2026-09-14.

(c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident

What an engagement reports against it
Destructive and state-changing actions sit behind the first of three approval gates, so what an engagement produces here is the conditions under which availability could be affected, evidenced, rather than a demonstration produced by causing the incident.

OJ L 119, 4.5.2016, p. 52. Read 2026-09-14. The gate applies on every class and in all three delivery models.

(d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing

What an engagement reports against it
The engagement itself, and the record it leaves: scope and authorisation, the artefact behind each finding, the severity with its vector, and the state each finding reached. This is the point the rest of this page is about.

OJ L 119, 4.5.2016, p. 52. Read 2026-09-14, in the Publications Office file of the signed Official Journal.

The clause

Four things in one sentence, and who is bound by them

Article 32(1)(d) reads, in the Official Journal text: “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.” Four things in it carry weight. It is a process. The measures are technical and organisational, so what is being evaluated is a whole programme and not only its technical half. The word is regularly, and the chapeau of Article 32(1) sets the terms on which the cadence is decided — taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. And the chapeau binds “the controller and the processor”, which means a processor carries Article 32 in its own right, alongside the contract terms Article 28(3) requires of it. Article 32(2) then supplies the measure of effectiveness: in assessing the appropriate level of security, account shall be taken in particular of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed. That is a yardstick about the data, which is why a severity score and a risk assessment are two documents rather than one.

The provisions

Every Article this page relies on, quoted and dated

Each row names the provision, what it provides, and the date the text was read. A clause number is the one thing on a compliance page a reader will go and check.

ProvisionWhat it provides
Article 32(1), chapeau The controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons — “including inter alia as appropriate” the points that follow.
OJ L 119, 4.5.2016, p. 51. Read 2026-09-14.
Article 32(1)(d) “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.” The subject of this page, quoted with the definite article the Official Journal text carries.
OJ L 119, 4.5.2016, p. 52. Read 2026-09-14.
Article 32(2) In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.
OJ L 119, 4.5.2016, p. 52. Read 2026-09-14.
Article 32(3) Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of this Article.
OJ L 119, 4.5.2016, p. 52. Read 2026-09-14. “An element” is the operative phrase, and the mechanisms named are the ones at Articles 40 and 42.
Article 32(4) The controller and processor shall take steps to ensure that any natural person acting under their authority who has access to personal data does not process them except on instructions from the controller, unless required to do so by Union or Member State law. It is the provision that governs anybody working inside your systems, testers included.
OJ L 119, 4.5.2016, p. 52. Read 2026-09-14.
Article 5(1)(f) Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures — the “integrity and confidentiality” principle. A security failure commonly engages this principle as well as Article 32.
OJ L 119, 4.5.2016, p. 35–36. Read 2026-09-14. Article 5 is listed at Article 83(5)(a), which is a different fine tier from the one below.
Article 28(3)(c), (f) and (h) The processor contract must provide that the processor takes all measures required pursuant to Article 32; assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36, taking into account the nature of processing and the information available to the processor; and allows for and contributes to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
OJ L 119, 4.5.2016, p. 49–50. Read 2026-09-14. The audit and inspection right at (h) is a term of the processor contract, held by the controller against its processor.
Article 83(4)(a) Infringements of the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43 are subject to administrative fines up to EUR 10 000 000, or in the case of an undertaking up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher. Article 32 falls inside the range “25 to 39”.
OJ L 119, 4.5.2016, p. 82–83. Read 2026-09-14. The EUR 20 000 000 / 4 % tier sits at Article 83(5), whose point (a) — the point read at source here — covers the basic principles for processing at Articles 5, 6, 7 and 9.

Article 32(1), chapeau

What it provides
The controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons — “including inter alia as appropriate” the points that follow.

OJ L 119, 4.5.2016, p. 51. Read 2026-09-14.

Article 32(1)(d)

What it provides
“a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.” The subject of this page, quoted with the definite article the Official Journal text carries.

OJ L 119, 4.5.2016, p. 52. Read 2026-09-14.

Article 32(2)

What it provides
In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.

OJ L 119, 4.5.2016, p. 52. Read 2026-09-14.

Article 32(3)

What it provides
Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of this Article.

OJ L 119, 4.5.2016, p. 52. Read 2026-09-14. “An element” is the operative phrase, and the mechanisms named are the ones at Articles 40 and 42.

Article 32(4)

What it provides
The controller and processor shall take steps to ensure that any natural person acting under their authority who has access to personal data does not process them except on instructions from the controller, unless required to do so by Union or Member State law. It is the provision that governs anybody working inside your systems, testers included.

OJ L 119, 4.5.2016, p. 52. Read 2026-09-14.

Article 5(1)(f)

What it provides
Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures — the “integrity and confidentiality” principle. A security failure commonly engages this principle as well as Article 32.

OJ L 119, 4.5.2016, p. 35–36. Read 2026-09-14. Article 5 is listed at Article 83(5)(a), which is a different fine tier from the one below.

Article 28(3)(c), (f) and (h)

What it provides
The processor contract must provide that the processor takes all measures required pursuant to Article 32; assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36, taking into account the nature of processing and the information available to the processor; and allows for and contributes to audits, including inspections, conducted by the controller or another auditor mandated by the controller.

OJ L 119, 4.5.2016, p. 49–50. Read 2026-09-14. The audit and inspection right at (h) is a term of the processor contract, held by the controller against its processor.

Article 83(4)(a)

What it provides
Infringements of the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43 are subject to administrative fines up to EUR 10 000 000, or in the case of an undertaking up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher. Article 32 falls inside the range “25 to 39”.

OJ L 119, 4.5.2016, p. 82–83. Read 2026-09-14. The EUR 20 000 000 / 4 % tier sits at Article 83(5), whose point (a) — the point read at source here — covers the basic principles for processing at Articles 5, 6, 7 and 9.

Sourcing

Where the text quoted on this page was read

Reading of Regulation (EU) 2016/679 As of 2026-09-14
  • Every Article quoted here was read in the English edition of the Regulation as published in the Official Journal, OJ L 119, 4 May 2016, pages 1 to 88. Article 32 sits at pages 51 to 52.
  • The copy read was the Publications Office’s own file of the signed Official Journal at op.europa.eu. On the read date, eur-lex.europa.eu was serving its Today’s OJ index page in place of every legal-content, ELI and CELEX address requested, so the issuing body’s own copy was used. For a stable public reference, the ELI for the Regulation is eur-lex.europa.eu/eli/reg/2016/679/oj.
  • The English corrigendum at OJ L 127, 23 May 2018, page 2 was read in full. Its corrections run to recital 71 and Articles 37(1)(c), 41(3), 41(5), 42(7), 43(3), 43(6), 57(1)(p), 64(1)(c), 64(6) to (8), 65(1)(a), 69(2), 70(1)(l), 70(1)(o) and 70(1)(p). The Article 32 wording quoted on this page is the wording of the Official Journal text.
  • Article 99 provides that the Regulation entered into force on the twentieth day following publication and applies from 25 May 2018. The text quoted here is therefore the text of 4 May 2016, and 25 May 2018 is the date it became applicable.
  • On the techniques by which the process is operated, the statement cited on this page is the UK Information Commissioner’s Office guide to data security, read 14 September 2026, which puts it that what the tests look like and how regularly you do them will depend on your own circumstances, that techniques such as vulnerability scanning and penetration testing can be used, and that testing can be undertaken internally or externally.

Deliberately excluded

  • The consolidated version behind EUR-Lex could not be opened on the read date, so the full list of acts amending the Regulation is not asserted here. What was checked at source is the single English corrigendum, whose corrections are listed above.
  • The ICO is the United Kingdom’s regulator reading the equivalent provision of the UK GDPR. It is cited on this page as that, and it is not an EU-level or European Data Protection Board position.
  • Nothing here is a determination of what your own processing requires. That is a determination for you, your DPO and your advisers, made on the terms Article 32(1) sets.

Whose signature

Which model to take when the report leaves your organisation

The eleven coverage classes and the evidence per finding are identical across all three. What changes is whether a senior Security Brigade auditor was inside the engagement and stands behind what came out of it.

Which model to take when the report leaves your organisation
StateWhat it meansWhat follows
Autonomous, expert verified Every finding is verified by a senior Security Brigade auditor before any of it reaches you, so a report going to a controller, to an enterprise customer’s security review or into a supervisory file has a named reviewer behind it. Start here where the report leaves your organisation.
Human led A senior auditor takes the engagement itself, with B-52 underneath — settles the scope, decides where the depth goes, and owns the report. The model for high-risk processing, or where the scope itself is the contested part. An auditor owns the engagement end to end.
Fully autonomous Terminal You authorise the scope and the targets, and nothing further is asked of you. Same classes, same artefact per finding, no auditor inside the engagement to review it. Built for the runs between verified engagements.
Key
  • A senior auditor is inside the engagement and behind the report
  • Scope sign-off, then nothing — no auditor review attaches to the output
  • TerminalNo state follows this one

Cadence

A process is made of more than one occasion

How often your process runs is a determination for you and your DPO, made on the terms the chapeau sets: the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risk to the rights and freedoms of natural persons. What we can tell you is what each run costs you to arrange. A single run against one application or target starts at $500, which is what makes a run between engagements a scheduling decision rather than a budget one. On the question of whether an unverified run is worth having in the record at all, there is a measurement: B-52 was run in parallel with Security Brigade’s expert assessment team against the same targets, the two sets of findings were pooled with each item counted once, and B-52 reached 90 to 95 per cent of that pooled set. The pattern that follows from those two facts is the common one — the autonomous model running between, and a verified engagement for the report that goes outside, because verification is what a reader outside your organisation is relying on.

What you receive

What the report carries for an Article 32 file

Per finding

The exchange, not the assertion

The request that triggered the finding and the response that came back, reproduced as sent and returned, with the portion that proves the defect marked and the steps set down so your own engineers can re-run them.

Per finding

A severity you can rebase

CVSS v4.0 with the vector printed, plus the CWE. The vector is there because Article 32(2) measures risk to the personal data, and that recalculation is yours to make against the processing the finding touches.

Per engagement

Scope, authorisation and the gates

The scope as agreed, the person who authorised it, the dates the testing ran, and the decision recorded at each of the three approval gates while it did — destructive or state-changing actions, persistence and movement past the entry host, and live credentials or real customer data.

If you are a processor

Something to put in front of the controller

Article 28(3)(h) is a contract right your controller holds against you as its processor. What an engagement leaves you is a document to put in front of them when it is exercised, and evidence for the assistance duty at Article 28(3)(f).

Closure

The four states a finding passes through

The order carries the argument. Each state is a different claim, and only the last one is made by us rather than by you.

The boundary

What this page claims, and where it stops

Article 32 is easy to round up and hard to walk back once it has been rounded. These are the four places this page holds its line.

The position
Mapping, not issuing Findings are mapped to the provisions named above. Certification under the Article 42 mechanism is issued to controllers and processors by the bodies accredited for that purpose, and Article 32(3) treats adherence to an approved Article 40 code or an approved Article 42 mechanism as an element by which to demonstrate compliance with Article 32(1). A report from an engagement is evidence you hold, and it is described here as that.
What Security Brigade holds CERT-In empanelment since 2008, and ISO 27001 certification. Those are the two instruments this site claims, they belong to Security Brigade as the firm delivering the engagement, and the B-52 platform holds none of its own.
Whose determination it is Which measures are appropriate to your processing, how often your process runs, and whether what you hold satisfies your supervisory authority are determinations for you, your DPO and your advisers, made on the terms Article 32(1) sets. What is stated here is what an engagement produces.
Where our people sit Article 32(4) requires the controller and processor to take steps to ensure that any natural person acting under their authority who has access to personal data processes them only on instructions from the controller, unless Union or Member State law requires otherwise. An engagement runs under a written scope, and the third approval gate covers live credentials and real customer data specifically.

Mapping, not issuing

The position
Findings are mapped to the provisions named above. Certification under the Article 42 mechanism is issued to controllers and processors by the bodies accredited for that purpose, and Article 32(3) treats adherence to an approved Article 40 code or an approved Article 42 mechanism as an element by which to demonstrate compliance with Article 32(1). A report from an engagement is evidence you hold, and it is described here as that.

What Security Brigade holds

The position
CERT-In empanelment since 2008, and ISO 27001 certification. Those are the two instruments this site claims, they belong to Security Brigade as the firm delivering the engagement, and the B-52 platform holds none of its own.

Whose determination it is

The position
Which measures are appropriate to your processing, how often your process runs, and whether what you hold satisfies your supervisory authority are determinations for you, your DPO and your advisers, made on the terms Article 32(1) sets. What is stated here is what an engagement produces.

Where our people sit

The position
Article 32(4) requires the controller and processor to take steps to ensure that any natural person acting under their authority who has access to personal data processes them only on instructions from the controller, unless Union or Member State law requires otherwise. An engagement runs under a written scope, and the third approval gate covers live credentials and real customer data specifically.

Put the process on a cadence you can defend

A scoping call settles what the engagement covers, which delivery model the report needs to come from, and how the runs in between are arranged. Where the report goes to a controller, a customer or a supervisory file, start from the expert-verified model.