What the regulation requires
The General Data Protection Regulation (Regulation (EU) 2016/679) governs the processing of personal data in the European Union and has applied since May 2018. It covers organizations established in the EU, and organizations outside the EU that offer goods or services to people in the EU or monitor their behavior there. It applies to both controllers, which decide why and how personal data is processed, and processors, which process it on a controller's behalf.
Security is one of its core principles. Article 5 requires integrity and confidentiality of personal data, and Article 32 requires technical and organizational measures appropriate to the risk. Organizations work on GDPR security to meet these duties, to answer customer due diligence, and to be ready for a breach or a question from a supervisory authority.
Articles that shape security work
Article 32: security of processing
Measures appropriate to the risk, including as appropriate pseudonymization and encryption, ongoing confidentiality, integrity, availability and resilience, timely restoration after an incident, and regular testing of the measures.
Article 30: records of processing
Controllers and processors keep records of processing activities, with a limited exemption for some smaller organizations. Where possible these include a general description of the security measures.
Article 35: DPIA
A data protection impact assessment is required before processing likely to result in a high risk to people's rights and freedoms. It includes the measures planned to address the risks.
Article 33: breach notification
A controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk. A processor notifies the controller without undue delay.
Article 34: informing individuals
When a breach is likely to result in a high risk to individuals, the controller also informs the people affected without undue delay.
Article 25 and Article 28
Article 25 requires data protection by design and by default. Article 28 requires controllers to use processors that give sufficient guarantees, under a written contract.
How the work runs with us
We agree which systems, products and processing activities are in scope, and confirm with your DPO or counsel whether you act as controller, processor or both for each. You receive a scope statement and a plan with dates.
We map personal data across systems, vendors and locations, and review current security measures against Article 32 and your own risk assessment. Each gap is recorded with its risk to individuals, the systems affected and the effort to close it.
We turn the gaps into a prioritized remediation plan. Our engineers implement or improve measures such as access control, encryption, logging, backups and deletion routines. We update security policies and the breach response procedure where needed, for review by your DPO and counsel.
We organize evidence of the security measures so your DPO can reference it in records of processing, DPIAs and customer responses. We test selected measures, which supports the Article 32 duty to test regularly. Retainers are available for ongoing support.
What you receive
Each engagement has a fixed scope agreed in writing. The deliverables below are typical. The exact set depends on your scope.
Data map
- Systems, vendors and locations holding personal data
- Data flows between them
- Input for your records of processing
Security gap assessment
- Current measures compared with Article 32
- Gaps ranked by risk to individuals
- Owner suggested for each item
Remediation
- Prioritized remediation plan
- Measures implemented by our engineers
- Updated security policies and breach procedure
Evidence
- Description of security measures for records and DPIAs
- Control test results
- Material for customer due diligence
Security measures we help implement
These areas support Article 32 and data protection by design. We work inside your existing systems where possible.
Data mapping
An inventory of personal data, where it lives, who can reach it and which vendors receive it.
Access control and identity
Single sign-on, multi-factor authentication, least privilege and access reviews. We can deploy Keycloak in your own environment where it fits.
Encryption and pseudonymization
Encryption at rest and in transit, key management, and pseudonymization where it suits the processing.
Logging and monitoring
Logs and alerts that help detect and investigate breaches. We can deploy Wazuh in your own environment where it fits.
Breach response
Detection, triage and escalation steps that give your DPO the facts needed within the 72-hour window. We also offer incident response training.
Backup and recovery
Backups and restore tests that support the ability to restore access to personal data in a timely manner.
Vendor risk
Security review of processors and sub-processors, and tracking of the security terms in their contracts.
Security testing
Vulnerability management and penetration testing as part of regularly testing the effectiveness of measures.
Controller and processor security duties
A summary of security-related duties. Your counsel or DPO confirms which role applies to each processing activity.
| Topic | Controller | Processor |
|---|---|---|
| Security of processing (Art. 32) | Implements appropriate measures | Implements appropriate measures |
| Records (Art. 30) | Keeps records of processing activities | Keeps records of processing carried out for each controller |
| Choosing partners (Art. 28) | Uses only processors that give sufficient guarantees, under a written contract | Engages sub-processors only with the controller's authorization and passes on the same obligations |
| Breach (Art. 33 and 34) | Notifies the supervisory authority and, where required, affected individuals | Notifies the controller without undue delay |
| DPIA (Art. 35) | Carries out the DPIA where required | Assists the controller with the DPIA |
| Instructions | Sets the purposes and means of processing | Processes only on documented instructions from the controller |
Who does what
We map data, assess security measures, implement agreed controls, update security policies, organize evidence and test controls. Your team owns the systems, runs the measures day to day and keeps records current.
We are not a law firm and do not give legal advice. Your DPO and legal counsel decide on lawful bases, controller and processor roles, the content of contracts and transfer mechanisms, and whether a breach must be notified. Supervisory authorities enforce GDPR. We do not issue GDPR certifications. We work alongside your DPO, counsel and compliance platform.
Common questions
How long does it take?
It depends on the number of systems, processing activities and vendors in scope, and on how much remediation is needed. We agree a plan with dates during scoping.
Can you make us GDPR compliant?
GDPR compliance covers legal, organizational and technical duties. We cover the security and technical side and work with your DPO and counsel, who own the legal side.
What counts as appropriate security under Article 32?
GDPR does not list fixed controls. Measures depend on the state of the art, costs, the nature and purposes of processing, and the risk to individuals. We help your team document that reasoning and the measures chosen.
Can you help us meet the 72-hour breach deadline?
We help you build detection, triage and escalation steps so your DPO gets the facts quickly. The decision to notify and the notice itself belong to your DPO and counsel.
Can you sign an NDA or a data processing agreement?
We sign an NDA on request. If the work requires access to personal data, we agree the terms with your team and counsel during scoping.
Do you offer ongoing support?
Yes. Engagements have a fixed scope, and we offer retainers for control testing, data map updates and evidence upkeep.
How to prepare
Gather your records of processing activities, recent DPIAs, security policies, your breach response procedure, a list of processors and sub-processors, and any recent audit or penetration test reports.
Introduce us to your DPO or privacy lead and name the owners of identity, infrastructure, applications and vendor management. Let us know about customer due diligence requests or deadlines that drive the work.
International transfers
Chapter V of GDPR governs transfers of personal data to countries outside the European Economic Area. Transfers can rely on an adequacy decision by the European Commission (Article 45), on appropriate safeguards such as standard contractual clauses or binding corporate rules (Articles 46 and 47), or on specific derogations (Article 49).
Your counsel chooses the transfer mechanism. Our part is technical: showing where data is stored and processed, which vendors receive it, and which measures such as encryption and access control apply. A private deployment of open-source tools in a region you choose can reduce the number of transfers to review.

