UK GDPR Article 32: security of processing, item by item
“The UK GDPR does not define the security measures that you should have in place. It requires you to have a level of security that is ‘appropriate’ to the risks presented by your processing.” — ICO, A guide to data security.
Article 32 is the security article of UK GDPR. It is short, it names four measures, and it deliberately does not tell you which products or controls to use. This page quotes it in full and puts the Information Commissioner's own guidance next to each part, so you can see what is required and what is left to your judgement.
The four measures, and what the ICO says about each
Article 32(1): “Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:”
| Article 32(1) | The ICO on this point | |
|---|---|---|
| a | the pseudonymisation and encryption of personal data | “Pseudonymisation and encryption are specified in the UK GDPR as two examples of measures that may be appropriate for you to implement. This does not mean that you are obliged to use these measures.” |
| b | the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services | On resilience: “This refers to things like business continuity plans, disaster recovery, and cyber resilience.” |
| c | the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident | “The UK GDPR does not define what a ‘timely manner’ should be.” It depends on who you are, your systems and the risk. |
| d | a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing | “Importantly, it does not specify the type of testing, nor how regularly you should undertake it.” |
(a) Pseudonymisation and encryption
“Pseudonymisation and encryption are specified in the UK GDPR as two examples of measures that may be appropriate for you to implement. This does not mean that you are obliged to use these measures.” The words “as appropriate” in the article matter: both are examples, chosen according to the risk. On encryption specifically the ICO is clearer: “if you are storing personal data, or transmitting it over the internet, we recommend that you use encryption and have a suitable policy in place, taking account of the residual risks involved.”
Where an ISMS helps (our reading)
In an ISO 27001 management system, whether and where to use cryptography is a risk-treatment decision, recorded with its reasons in the Statement of Applicability. That record is the kind of documented analysis the ICO asks for when it says you should “undertake a risk analysis and document your findings”.
(b) Confidentiality, integrity, availability and resilience
The ICO calls the first three the “CIA triad” and adds that resilience means whether systems can keep operating under adverse conditions and be restored. “This refers to things like business continuity plans, disaster recovery, and cyber resilience.”
Where an ISMS helps (our reading)
ISO 27001's risk assessment is built on exactly these properties: it requires risks to be identified for “the loss of confidentiality, integrity and availability for information within the scope” of the management system. Resilience is addressed through the continuity controls a risk treatment selects.
(c) Restoring access in a timely manner
“The UK GDPR does not define what a ‘timely manner’ should be.” What counts as timely depends on who you are, what systems you run and the risk to people if the data is unavailable. The ICO's worked example is an organisation using the “3-2-1” backup strategy: ransomware reaches two of its three copies, and the off-site third copy lets it restore its systems in a timely manner. The point is that the decision was made in advance, in the risk assessment, not during the incident.
(d) Testing, assessing and evaluating
This is the part people miss. “Yes, the UK GDPR specifically requires you to have a process for regularly testing, assessing and evaluating the effectiveness of any measures you put in place.” And: “Technically, you can undertake this through a number of techniques, such as vulnerability scanning and penetration testing.” But “Importantly, it does not specify the type of testing, nor how regularly you should undertake it.”
Where an ISMS helps (our reading)
A certified ISO 27001 management system has a built-in cycle for evaluating whether its measures work: monitoring and measurement, an internal audit programme, a management review, and an external surveillance audit every year. That is not the same as a penetration test, and an ISMS does not replace technical testing; it is the process that decides what to test and acts on the results.
How much security is “appropriate”
“The UK GDPR does not define the security measures that you should have in place. It requires you to have a level of security that is ‘appropriate’ to the risks presented by your processing.” The article lists the factors: the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to people. Article 32(2) adds: “In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.”
The ICO's first instruction follows from that: “So, before deciding what measures are appropriate, you need to assess your information risk.”
Organisational measures
The ICO lists an information risk assessment, a security-aware culture, and a named person with day-to-day responsibility and the authority to act. On policy it is pragmatic: “Although an information security policy is an example of an appropriate organisational measure, you may not need a ‘formal’ policy document or an associated set of policies in specific areas.”
Technical measures
“Technical measures therefore include both physical and computer or IT security.” Doors, locks and the disposal of paper records sit alongside network and system security.
Sector rules
Where a sector sets its own security requirements, the ICO takes them into account: “Although following these requirements will not necessarily equate to compliance with the UK GDPR’s security principle, the ICO will nevertheless consider these carefully in any considerations of regulatory action.” Its example is the payment card industry's PCI DSS.
Paragraphs 3 and 4
Certification
“Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as a means of demonstrating compliance with the requirements set out in paragraph 1 of this Article.” Those words were substituted by the Data (Use and Access) Act 2025 from 20 August 2025. The ICO: “It is important that you check carefully that the code or certification scheme has been approved by the ICO.” What an approved certification is, and how it differs from ISO 27001, is on UK GDPR certification.
People
Article 32(4): “The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by domestic law.” In practice that means instructions and training — the ICO lists refresher training, identifying callers and recognising phishing among the topics.
Processors carry Article 32 too
Article 32(1) applies to “the controller and the processor”, and every processor contract must require the processor to take the Article 32 measures. See Article 28.
We do not give legal advice, audit or certify, and are paid the same fixed fee per enquiry whichever firm you use. The law is quoted from legislation.gov.uk and the guidance from the ICO's website; for advice on your own processing, speak to a data protection professional.
Where this fits
Common questions
What does Article 32 of UK GDPR say?
That controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks to people. It lists four measures “as appropriate”: pseudonymisation and encryption; ongoing confidentiality, integrity, availability and resilience; timely restoration after an incident; and a process for regularly testing and evaluating the measures.
Is encryption mandatory under UK GDPR?
Not in every case. The ICO: “Pseudonymisation and encryption are specified in the UK GDPR as two examples of measures that may be appropriate for you to implement. This does not mean that you are obliged to use these measures.” But it also says: “if you are storing personal data, or transmitting it over the internet, we recommend that you use encryption and have a suitable policy in place, taking account of the residual risks involved.”
What are technical and organisational measures?
The measures Article 32 requires. The ICO describes organisational measures such as an information risk assessment, a named person responsible for security, and staff training, and says technical measures cover more than IT: “Technical measures therefore include both physical and computer or IT security.”
Do we have to do penetration testing under UK GDPR?
You must test. “Yes, the UK GDPR specifically requires you to have a process for regularly testing, assessing and evaluating the effectiveness of any measures you put in place.” How is up to you: “Technically, you can undertake this through a number of techniques, such as vulnerability scanning and penetration testing.” and “Importantly, it does not specify the type of testing, nor how regularly you should undertake it.”
Do we need an information security policy?
Not necessarily a formal one. “Although an information security policy is an example of an appropriate organisational measure, you may not need a ‘formal’ policy document or an associated set of policies in specific areas.” It depends on your size and the data you process.
Does ISO 27001 satisfy Article 32?
No certificate satisfies it by itself, and the ICO's security guide does not name ISO 27001. Article 32(3) names “an approved certification mechanism as referred to in Article 42”. An ISO 27001 management system is a structured way of deciding on, running and testing the measures Article 32 asks for — for the processing inside its scope.
Does Article 32 apply to processors as well as controllers?
Yes. Article 32(1) says “the controller and the processor shall implement”, and Article 28 requires every processor contract to say the processor “takes all measures required pursuant to Article 32”.
Sources cited on this page
- UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
- ICO, A guide to data security
- UK GDPR Article 28 (Processor), legislation.gov.uk
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Need to evidence your Article 32 measures?
Say what personal data you process and whether you already hold ISO 27001 or Cyber Essentials.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.