Frameworks / GDPR / GDPR-Art.32 GDPR
Chapter IV - Controller and Processor
GDPR GDPR-Art.32: Security of processing Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Take steps to ensure that any person acting under the controller's or processor's authority who has access to personal data processes it only on instructions.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 19 August 2026 What else in your programme already covers this This control maps to 185 controls across 76 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment AUCDR-IS-2 Secure the network and systems within the data environment AUCDR-IS-4 Formal vulnerability management program AUCDR-IS-5 Limit, prevent, detect and remove malware AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-P4.3 P4.3 Securely disposing of personal information CBPR-06 Security Safeguards CBPR-PR-27 Physical, technical and administrative safeguards CBPR-PR-28 Safeguards proportional to risk CBPR-PR-30 Specific proportional safeguards in place CBPR-PR-32 Detection, prevention and response measures CBPR-PR-33 Testing the effectiveness of safeguards ACC-4 ACC-4 Restrict access to access and time data to authorised staff with habilitations, traceability and strong authentication CALL-4 CALL-4 Limit access to recordings to the service pursuing the purpose, with authorisations and traceability GEO-4 GEO-4 Restrict geolocation data to authorised staff and do not give clients the driver's name GEO-5 GEO-5 Secure the geolocation platform and bind its provider by contract VID-4 VID-4 Secure remote viewing and do not use it to supervise work quality VID-6 VID-6 Limit viewing of images to authorised, trained persons and secure access 5.7.1 Monitoring, measurement, analysis and evaluation 6.7.1 Cryptographic controls 6.9.3 Backup 7.4.9 PII transmission controls 8.2.1 Customer agreement 8.4.3 PII transmission controls 5.30 ICT readiness for business continuity 5.34 Privacy and protection of personal identifiable information (PII) 5.35 Independent review of information security 8.13 Information backup 8.24 Use of cryptography 5.30 ICT readiness for business continuity 5.34 Privacy and protection of PII 5.35 Independent review of information security 8.13 Information backup 8.24 Use of cryptography Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure Art.21.2.c Business continuity, backup management, disaster recovery and crisis management Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption Art.21.2.i Human resources security, access control policies and asset management NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations C5-CRY-02 Encryption of data for transmission (transport encryption) C5-CRY-03 Encryption of sensitive data for storage C5-OPS-08 Data Backup and Recovery - Regular Testing C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures DORA-Art.12 Backup policies and procedures, restoration and recovery DORA-Art.24 General requirements for the performance of digital operational resilience testing DORA-Art.56 Data protection DORA-Art.9 Protection and prevention CA-7 Continuous Monitoring CP-10 System Recovery and Reconstitution SC-13 Cryptographic Protection SI-6 Security and Privacy Function Verification (SI-6) CA-7 Continuous Monitoring CP-10 System Recovery and Reconstitution SC-13 Cryptographic Protection SI-6 Security and Privacy Function Verification (SI-6) CRA-Art.13_AnnexI Manufacturer obligations and essential requirements (Article 13 + Annex I) CRA-Art.14_16 Reporting obligations and the single reporting platform (Articles 14 and 16) CRA-Art.31 Technical documentation (Article 31 + Annex VII) PSD2-Art.94 Data protection (PSD2 Article 94) - GDPR alignment PSD2-Art.95 Management of operational and security risks (PSD2 Article 95) PSD2-Art.97 Strong Customer Authentication (PSD2 Article 97) - knowledge / possession / inherence + dynamic linking EGY-PDPL-Art.13 DPO security duties for sensitive personal data EGY-PDPL-Art.4 Controller obligations EGY-PDPL-Art.5 Processor obligations ZDPA-07 Security of Processing ZDPA-17 Cybersecurity and Critical Information Infrastructure ZIMBABWE-3 Security and Cross-Border 3.1(e) 3.1(e) Security of monitoring data and staff awareness of data protection duties 5.4.2(b) 5.4.2(b) Bring your own device: secure the employer's data, weigh monitoring during personal use, or bar private use §1798.100 General Duties of Businesses that Collect Personal Information §1798.150 Private Right of Action for Data Breaches SD134-8 Security Safeguards SD134-9 Access Control CDR-PS-12 Privacy Safeguard 12: Security of CDR Data, and Destruction or De-identification CDR-RULE-SECURITY Information Security (CDR Rules Schedule 2) 5.2(c) 5.2(c) Biometric data security: compartmentalise, separate stores, encrypt, detect fraud, sign, no external access 9.3.2 9.3.2 Technical security: physical protection, secure transmission, encryption, access control and logging EMV3DS-20 Message security and key management EMV3DS-21 Cardholder data protection and minimisation EN303645-5.8 Ensure that personal data is secure EN303645-6 Data Protection Provisions for Consumer IoT (Clause 6) EUAI-Art.15 Accuracy, robustness and cybersecurity EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox DGA-Art.12 Conditions for providing data intermediation services (Article 12) DGA-Art.5_6 Conditions for re-use and fees (Articles 5-6) NCCS-Art.29_30_31 Common electricity cybersecurity framework and minimum cybersecurity controls (NCCS Articles 29-31) - for high-impact entities NCCS-Art.48_49_50 Information protection and classification (NCCS Articles 48-50) CPNI-64.2009 Safeguards required for use of CPNI (47 CFR 64.2009) CPNI-64.2011 Notification of CPNI security breaches (47 CFR 64.2011) 10.6 10.6 Need-to-know internal access 7.1 7.1 Reasonable security safeguards Art. 132-ter Art. 132-ter Secure communications services and traffic and location data with measures proportionate to risk Art. 2-septies(7) Art. 2-septies(7) Use biometrics for physical and logical access to data only within the safeguard measures UZB-DPL-12 Security of Personal Data UZB-DPL-13 Confidentiality Obligation AL-DPA-10 Security of Processing APP-11 APP 11 - Security of personal information AT-DSG-4 Section 6 - Data secrecy (Datengeheimnis) AZ-DPA-13 Article 14 - Security requirements BW-DPA-s32 Safeguards for processing of personal data COPPA-312.8 Confidentiality, Security, and Integrity (Written Information Security Program) CZ-110-§40 Zabezpeceni zpracovani (security of processing) CDMC-KC9 Security Controls RDCOC-PSE-01 Pseudonymisation Standards ESRB-PC-15 Confidentiality, security and integrity of child PI CSA-Art.8 Security of the Alert System (Article 8) EMFA-Art.4 Rights of media service providers (Article 4) - editorial independence, source protection, anti-spyware IVDR-Art.102_103_104 Confidentiality, data protection and Medical Device Coordination Group cooperation (Articles 102-104) ePD-Art.4 Security of services and personal-data-breach notification (Article 4) EST-IKS-§43-45 Security measures and breach notification in law enforcement processing UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) s64 s 64 Implement risk-based security measures, including the fourteen control objectives for automated processing CIA-SEC-08 Technical and physical safeguards 503.001(c)(2) 503.001(c)(2) Store, transmit and protect with reasonable care Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Chapter IV - Controller and Processor You are reading one control. How much of GDPR have you already done? GDPR GDPR-Art.32 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.
Query this from an agent The graph holds this control, the 185 it maps to, and the evidence behind each claim, over MCP and REST.