Definition · External Attack Surface Management
What is GDPR Article 32?
Article 32 of the General Data Protection Regulation is titled “Security of processing”. It is the provision that obliges both controllers and processors to secure personal data, and it applies alongside the UK GDPR and the Data Protection Act 2018 for organisations in the UK, where the Information Commissioner’s Office is the supervisory authority.
What the Article actually says
The duty is risk-based rather than prescriptive. Measures must be appropriate taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, against the risk to individuals. The Article names examples rather than a checklist:
- Pseudonymisation and encryption of personal data
- Ensuring the ongoing confidentiality, integrity, availability and resilience of processing systems
- The ability to restore availability and access after an incident
- A process for regularly testing, assessing and evaluating the effectiveness of security measures
That last point is the one most often overlooked. Article 32 does not merely ask for controls; it asks for a process that checks whether they are working.
How external exposure relates
Personal data is frequently reachable through internet-facing systems, so the externally visible layer is part of the appropriate-measures question. Encryption in transit maps onto TLS configuration and certificate validity. Confidentiality maps onto not leaving an admin panel, a database or an S3 bucket open. “Regularly testing” maps onto recurring scanning and penetration testing with recorded results, rather than a single assessment filed years ago.
Article 32 also reaches processors directly, which is why security questionnaires and contractual scanning commitments flow down supply chains.
Related concepts
Articles 33 and 34 cover breach notification and follow from a failure of Article 32 measures. See also NIS2 for the separate EU network security regime, ISO 27001 as an implementing framework, and vulnerability management.