| Article 32(1), chapeau | The controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons — “including inter alia as appropriate” the points that follow. |
| OJ L 119, 4.5.2016, p. 51. Read 2026-09-14. |
| Article 32(1)(d) | “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.” The subject of this page, quoted with the definite article the Official Journal text carries. |
| OJ L 119, 4.5.2016, p. 52. Read 2026-09-14. |
| Article 32(2) | In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed. |
| OJ L 119, 4.5.2016, p. 52. Read 2026-09-14. |
| Article 32(3) | Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of this Article. |
| OJ L 119, 4.5.2016, p. 52. Read 2026-09-14. “An element” is the operative phrase, and the mechanisms named are the ones at Articles 40 and 42. |
| Article 32(4) | The controller and processor shall take steps to ensure that any natural person acting under their authority who has access to personal data does not process them except on instructions from the controller, unless required to do so by Union or Member State law. It is the provision that governs anybody working inside your systems, testers included. |
| OJ L 119, 4.5.2016, p. 52. Read 2026-09-14. |
| Article 5(1)(f) | Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures — the “integrity and confidentiality” principle. A security failure commonly engages this principle as well as Article 32. |
| OJ L 119, 4.5.2016, p. 35–36. Read 2026-09-14. Article 5 is listed at Article 83(5)(a), which is a different fine tier from the one below. |
| Article 28(3)(c), (f) and (h) | The processor contract must provide that the processor takes all measures required pursuant to Article 32; assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36, taking into account the nature of processing and the information available to the processor; and allows for and contributes to audits, including inspections, conducted by the controller or another auditor mandated by the controller. |
| OJ L 119, 4.5.2016, p. 49–50. Read 2026-09-14. The audit and inspection right at (h) is a term of the processor contract, held by the controller against its processor. |
| Article 83(4)(a) | Infringements of the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43 are subject to administrative fines up to EUR 10 000 000, or in the case of an undertaking up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher. Article 32 falls inside the range “25 to 39”. |
| OJ L 119, 4.5.2016, p. 82–83. Read 2026-09-14. The EUR 20 000 000 / 4 % tier sits at Article 83(5), whose point (a) — the point read at source here — covers the basic principles for processing at Articles 5, 6, 7 and 9. |