GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.32: Security of processing

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Take steps to ensure that any person acting under the controller's or processor's authority who has access to personal data processes it only on instructions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 185 controls across 76 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AUCDR-IS-2 Secure the network and systems within the data environment
  • AUCDR-IS-4 Formal vulnerability management program
  • AUCDR-IS-5 Limit, prevent, detect and remove malware
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data

SOC 2 · 7 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • CBPR-06 Security Safeguards
  • CBPR-PR-27 Physical, technical and administrative safeguards
  • CBPR-PR-28 Safeguards proportional to risk
  • CBPR-PR-30 Specific proportional safeguards in place
  • CBPR-PR-32 Detection, prevention and response measures
  • CBPR-PR-33 Testing the effectiveness of safeguards
  • ACC-4 ACC-4 Restrict access to access and time data to authorised staff with habilitations, traceability and strong authentication
  • CALL-4 CALL-4 Limit access to recordings to the service pursuing the purpose, with authorisations and traceability
  • GEO-4 GEO-4 Restrict geolocation data to authorised staff and do not give clients the driver's name
  • GEO-5 GEO-5 Secure the geolocation platform and bind its provider by contract
  • VID-4 VID-4 Secure remote viewing and do not use it to supervise work quality
  • VID-6 VID-6 Limit viewing of images to authorised, trained persons and secure access

ISO 27701:2019 · 6 controls

  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 6.7.1 Cryptographic controls
  • 6.9.3 Backup
  • 7.4.9 PII transmission controls
  • 8.2.1 Customer agreement
  • 8.4.3 PII transmission controls

ISO 27001:2022 · 5 controls

  • 5.30 ICT readiness for business continuity
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 5.35 Independent review of information security
  • 8.13 Information backup
  • 8.24 Use of cryptography

ISO 27002:2022 · 5 controls

  • 5.30 ICT readiness for business continuity
  • 5.34 Privacy and protection of PII
  • 5.35 Independent review of information security
  • 8.13 Information backup
  • 8.24 Use of cryptography

NIS2 Directive · 5 controls

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • Art.21.2.i Human resources security, access control policies and asset management
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

NIST SP 800-53 Rev 5 · 5 controls

C5 (Germany) · 4 controls

  • C5-CRY-02 Encryption of data for transmission (transport encryption)
  • C5-CRY-03 Encryption of sensitive data for storage
  • C5-OPS-08 Data Backup and Recovery - Regular Testing
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

DORA · 4 controls

  • DORA-Art.12 Backup policies and procedures, restoration and recovery
  • DORA-Art.24 General requirements for the performance of digital operational resilience testing
  • DORA-Art.56 Data protection
  • DORA-Art.9 Protection and prevention

FedRAMP High · 4 controls

  • CA-7 Continuous Monitoring
  • CP-10 System Recovery and Reconstitution
  • SC-13 Cryptographic Protection
  • SI-6 Security and Privacy Function Verification (SI-6)

FedRAMP Moderate · 4 controls

  • CA-7 Continuous Monitoring
  • CP-10 System Recovery and Reconstitution
  • SC-13 Cryptographic Protection
  • SI-6 Security and Privacy Function Verification (SI-6)

APPI · 3 controls

Canadian PIPEDA · 3 controls

  • CRA-Art.13_AnnexI Manufacturer obligations and essential requirements (Article 13 + Annex I)
  • CRA-Art.14_16 Reporting obligations and the single reporting platform (Articles 14 and 16)
  • CRA-Art.31 Technical documentation (Article 31 + Annex VII)
  • PSD2-Art.94 Data protection (PSD2 Article 94) - GDPR alignment
  • PSD2-Art.95 Management of operational and security risks (PSD2 Article 95)
  • PSD2-Art.97 Strong Customer Authentication (PSD2 Article 97) - knowledge / possession / inherence + dynamic linking
  • EGY-PDPL-Art.13 DPO security duties for sensitive personal data
  • EGY-PDPL-Art.4 Controller obligations
  • EGY-PDPL-Art.5 Processor obligations
  • ZDPA-07 Security of Processing
  • ZDPA-17 Cybersecurity and Critical Information Infrastructure
  • ZIMBABWE-3 Security and Cross-Border
  • 3.1(e) 3.1(e) Security of monitoring data and staff awareness of data protection duties
  • 5.4.2(b) 5.4.2(b) Bring your own device: secure the employer's data, weigh monitoring during personal use, or bar private use

CCPA/CPRA · 2 controls

  • §1798.100 General Duties of Businesses that Collect Personal Information
  • §1798.150 Private Right of Action for Data Breaches
  • SD134-8 Security Safeguards
  • SD134-9 Access Control
  • CDR-PS-12 Privacy Safeguard 12: Security of CDR Data, and Destruction or De-identification
  • CDR-RULE-SECURITY Information Security (CDR Rules Schedule 2)
  • 5.2(c) 5.2(c) Biometric data security: compartmentalise, separate stores, encrypt, detect fraud, sign, no external access
  • 9.3.2 9.3.2 Technical security: physical protection, secure transmission, encryption, access control and logging
  • EMV3DS-20 Message security and key management
  • EMV3DS-21 Cardholder data protection and minimisation

ETSI EN 303 645 · 2 controls

  • EN303645-5.8 Ensure that personal data is secure
  • EN303645-6 Data Protection Provisions for Consumer IoT (Clause 6)

EU AI Act · 2 controls

  • EUAI-Art.15 Accuracy, robustness and cybersecurity
  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
  • DGA-Art.12 Conditions for providing data intermediation services (Article 12)
  • DGA-Art.5_6 Conditions for re-use and fees (Articles 5-6)
  • NCCS-Art.29_30_31 Common electricity cybersecurity framework and minimum cybersecurity controls (NCCS Articles 29-31) - for high-impact entities
  • NCCS-Art.48_49_50 Information protection and classification (NCCS Articles 48-50)
  • CPNI-64.2009 Safeguards required for use of CPNI (47 CFR 64.2009)
  • CPNI-64.2011 Notification of CPNI security breaches (47 CFR 64.2011)
  • 10.6 10.6 Need-to-know internal access
  • 7.1 7.1 Reasonable security safeguards
  • Art. 132-ter Art. 132-ter Secure communications services and traffic and location data with measures proportionate to risk
  • Art. 2-septies(7) Art. 2-septies(7) Use biometrics for physical and logical access to data only within the safeguard measures
  • UZB-DPL-12 Security of Personal Data
  • UZB-DPL-13 Confidentiality Obligation
  • AL-DPA-10 Security of Processing
  • APP-11 APP 11 - Security of personal information
  • AT-DSG-4 Section 6 - Data secrecy (Datengeheimnis)
  • AZ-DPA-13 Article 14 - Security requirements

Bahrain PDPL · 1 control

  • BW-DPA-s32 Safeguards for processing of personal data

COPPA · 1 control

  • COPPA-312.8 Confidentiality, Security, and Integrity (Written Information Security Program)
  • CZ-110-§40 Zabezpeceni zpracovani (security of processing)
  • ESRB-PC-15 Confidentiality, security and integrity of child PI
  • CSA-Art.8 Security of the Alert System (Article 8)
  • EMFA-Art.4 Rights of media service providers (Article 4) - editorial independence, source protection, anti-spyware
  • IVDR-Art.102_103_104 Confidentiality, data protection and Medical Device Coordination Group cooperation (Articles 102-104)
  • ePD-Art.4 Security of services and personal-data-breach notification (Article 4)
  • EST-IKS-§43-45 Security measures and breach notification in law enforcement processing
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • s64 s 64 Implement risk-based security measures, including the fourteen control objectives for automated processing
  • CIA-SEC-08 Technical and physical safeguards
  • 503.001(c)(2) 503.001(c)(2) Store, transmit and protect with reasonable care

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.32 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 185 it maps to, and the evidence behind each claim, over MCP and REST.