Point of law
Technical and organisational measures
Art. 32 GDPR requires a level of security appropriate to the risk and names criteria rather than a list. Appropriate means weighing the state of the art, the costs, the nature and purposes of the processing and the likelihood and severity of the risk against one another. An enumeration of measures without that weighing does not satisfy the provision.
What the provision requires
The provision is deliberately open. It names four objectives and five weighing criteria and leaves the selection to the controller. The task is therefore not one of ticking boxes but one of giving reasons.
Confidentiality
Access only for those authorised. The most effective lever sits in the authorisation concept, because the most common incident in practice is access by an unauthorised person from within the organisation.
Integrity
Data remain intact, and changes are traceable. Logging is a means here and at the same time a subject of the weighing exercise in its own right.
Availability and resilience
The service withstands load and disruption. For data protection it also matters that data subject rights remain capable of being met where a system fails.
Restoration
The state can be restored after an incident. A backup that has never been restored is an assumption and not evidence.
Where the line runs
Art. 32 GDPR and sec. 30 BSIG call for largely the same measures and assess them differently.
Art. 32 GDPR against sec. 30 BSIG
| Art. 32 GDPR | Merkmal | Sec. 30 BSIG |
|---|---|---|
| rights of data subjects | What is protected | functioning of the service |
| appropriate to the riskFive weighing criteria and four objectives, but no list. Appropriate means reasoned rather than complete. | Yardstick | state of the art, proportionate |
| accountability, Art. 5(2) | Evidence | spricht in dieser Zeile dafürproof to the BSIEssential entities demonstrate implementation to the BSI, and operators of critical installations do so recurrently. |
| keep it short | Log retention | keep it long |
| every controller | Addressee | only entities in scope |
The fourth row is the actual conflict. Security speaks for a long period, data protection for a short one, and the decision is a balance that would have to be reasoned and documented.
Where it stalls in practice
On the missing link between processing and measure. The measures are described for IT as a whole, the processing operations sit in the record, and there is no mapping between them. For an individual operation it therefore cannot be said which level of protection applies.
How we support you with technical and organisational measures
Grading by protection need is the usual route. Each operation in the record receives a grade, and each grade carries a set of measures. That creates the link without every operation having to be assessed individually.
For the evidence a short document per grade suffices, stating the risk considered, the measures taken and the alternatives rejected. In an audit it is the answer to the question about appropriateness.
Frequently asked questions
Is there a minimum list?
Art. 32(1) GDPR names four examples, namely pseudonymisation and encryption, confidentiality, integrity, availability and resilience, restoration, and a process for regular testing. That is not an exhaustive list but an enumeration of objectives.
How do we evidence appropriateness?
Through documenting the weighing exercise. What would have to be recorded is the risk considered, the measures weighed, the decision taken and its reason. That document is what a supervisory authority asks for, not the list itself.
How often does testing have to happen?
Art. 32(1)(d) GDPR requires a process for regular testing but names no period. An annual cycle is common, supplemented by a review after an incident or a material change.
More questions from this area
Implementing NIS2
The ten subjects in section 30(2) BSIG are the minimum scope, and their depth is measured by the five factors in section 30(1) sentence 2 BSIG.
SOC and SIEM
A system for evaluating security events processes large volumes of data about the conduct of staff, as a side effect of its purpose.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.