Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Point of law

Technical and organisational measures

Art. 32 GDPR requires a level of security appropriate to the risk and names criteria rather than a list. Appropriate means weighing the state of the art, the costs, the nature and purposes of the processing and the likelihood and severity of the risk against one another. An enumeration of measures without that weighing does not satisfy the provision.

What the provision requires

The provision is deliberately open. It names four objectives and five weighing criteria and leaves the selection to the controller. The task is therefore not one of ticking boxes but one of giving reasons.

Confidentiality

Access only for those authorised. The most effective lever sits in the authorisation concept, because the most common incident in practice is access by an unauthorised person from within the organisation.

Integrity

Data remain intact, and changes are traceable. Logging is a means here and at the same time a subject of the weighing exercise in its own right.

Availability and resilience

The service withstands load and disruption. For data protection it also matters that data subject rights remain capable of being met where a system fails.

Restoration

The state can be restored after an incident. A backup that has never been restored is an assumption and not evidence.

Where the line runs

Art. 32 GDPR and sec. 30 BSIG call for largely the same measures and assess them differently.

Art. 32 GDPR against sec. 30 BSIG

Art. 32 GDPRMerkmalSec. 30 BSIG
rights of data subjectsWhat is protectedfunctioning of the service
appropriate to the riskFive weighing criteria and four objectives, but no list. Appropriate means reasoned rather than complete.Yardstickstate of the art, proportionate
accountability, Art. 5(2)Evidencespricht in dieser Zeile dafürproof to the BSIEssential entities demonstrate implementation to the BSI, and operators of critical installations do so recurrently.
keep it shortLog retentionkeep it long
every controllerAddresseeonly entities in scope

The fourth row is the actual conflict. Security speaks for a long period, data protection for a short one, and the decision is a balance that would have to be reasoned and documented.

Where it stalls in practice

On the missing link between processing and measure. The measures are described for IT as a whole, the processing operations sit in the record, and there is no mapping between them. For an individual operation it therefore cannot be said which level of protection applies.

How we support you with technical and organisational measures

Grading by protection need is the usual route. Each operation in the record receives a grade, and each grade carries a set of measures. That creates the link without every operation having to be assessed individually.

For the evidence a short document per grade suffices, stating the risk considered, the measures taken and the alternatives rejected. In an audit it is the answer to the question about appropriateness.

Frequently asked questions

Is there a minimum list?

Art. 32(1) GDPR names four examples, namely pseudonymisation and encryption, confidentiality, integrity, availability and resilience, restoration, and a process for regular testing. That is not an exhaustive list but an enumeration of objectives.

How do we evidence appropriateness?

Through documenting the weighing exercise. What would have to be recorded is the risk considered, the measures weighed, the decision taken and its reason. That document is what a supervisory authority asks for, not the list itself.

How often does testing have to happen?

Art. 32(1)(d) GDPR requires a process for regular testing but names no period. An annual cycle is common, supplemented by a review after an incident or a material change.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.