Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations decide which technical and organisational…
Governance, Ownership & Risk

How should organisations decide which technical and organisational measures are appropriate under GDPR Article 32?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Governance, Ownership & Risk

Organisations should choose controls by balancing the state of the art, implementation cost, the nature and scope of processing, and the risk to individuals’ rights and freedoms. Article 32 does not demand absolute security. It requires measures that are proportionate to the data, the processing context, and the foreseeable threats, then reviewed as risk changes.

How to decide what Article 32 measures are appropriate

Article 32 is a proportionality test, not a checklist. The right control set is the one that fits the sensitivity of the data, the realistic threat model, the size and complexity of the processing, and the practical cost of implementing and maintaining the safeguard. That means two organisations can both be compliant while using different measures, provided each can justify the choice.

The decision should start with the processing context: what data is involved, who can access it, where it moves, and what would happen if confidentiality, integrity, or availability were lost. A low-risk internal system may justify simpler controls, while a high-impact processing operation, such as health, finance, or large-scale profiling, usually needs stronger technical and organisational measures and tighter review discipline.

Article 32 also expects organisations to match the safeguard to the way risk changes over time. A measure that is reasonable at launch can become insufficient after a system expansion, a new vendor integration, a new data category, or a material rise in threat activity. In practice, the appropriate control is the one that remains defensible when the processing grows, not just the one that looked adequate on day one. For identity and access controls in regulated environments, NHIMG’s Identity Security Regulatory Map is a useful way to translate that proportionality into concrete control choices.

What “state of the art” means in practice

State of the art does not mean buying the newest tool or adopting every available control. It means using measures that are reasonably current and credible for the risk, such as strong access control, encryption where appropriate, logging, backup, secure configuration, and tested recovery. Article 32 gives organisations flexibility, but it also expects them to understand what is normally achievable for the type of processing they run.

The most common mistake is to treat “state of the art” as a marketing claim rather than an operational benchmark. A control is only useful if it is actually deployed, monitored, and supported by a process that keeps it effective. That includes patching, configuration governance, access review, and incident response, not just initial deployment.

Where privacy obligations overlap with identity and data handling, the control choice should also reflect how personal data is minimised, classified, and retained. NHIMG’s Identity Data Privacy and Consent Guide is directly relevant when the organisation needs to justify access, retention, and lawful handling decisions around personal data.

How to document and defend the decision

The strongest Article 32 decisions are easy to explain after the fact. A good record shows the risk factors considered, the measures chosen, the reason those measures were proportionate, and the conditions that would trigger a reassessment. That is especially important when management, auditors, regulators, or incident responders later ask why a particular control set was judged sufficient.

Organisations should be able to point to the logic behind the choice, not just the control names. For example, if the data is low sensitivity and tightly bounded, the justification may support a lighter control set; if the processing is large-scale or exposed to external attack paths, the explanation should show why stronger protection, monitoring, or resilience measures were selected. The key question is whether the chosen safeguards materially reduce the actual risk to individuals’ rights and freedoms.

For teams that need a broader compliance view across multiple regimes, NHIMG’s regulatory map for identity security helps anchor control selection against overlapping obligations rather than treating GDPR in isolation.

Risk and Threat Considerations

Article 32 decisions fail when organisations either under-protect high-risk processing or over-rotate into controls they cannot sustain. Weaknesses usually appear where access is too broad, encryption or backup assumptions are not tested, or monitoring is too shallow to detect misuse, loss, or service degradation before individuals are affected.

Failure mechanism: The organisation misjudges the processing risk, chooses controls that are too weak for the actual exposure, or adopts controls that look strong on paper but are not operationally effective. Over time, that gap widens as systems, vendors, or threat conditions change.

Impact: Personal data may be exposed, altered, or unavailable, and the organisation may lose the ability to show that its safeguards were proportionate, current, and effective. That increases regulatory, operational, and trust consequences if an incident occurs.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt.32 — Security of ProcessingArticle 32 directly governs the proportionate choice of technical and organisational measures.
Art.25 — Data Protection by Design and by DefaultAppropriate measures under Article 32 are strengthened by embedding protection into system design.
Recommendation — Document why chosen measures are proportionate to risk, processing scope, and implementation cost. Build privacy controls into the default design and operating model of the processing.
NIST SP 800-53 Rev 5RA-3 — Risk AssessmentSelecting appropriate measures depends on identifying and evaluating the processing risk first.
SC-13 — Cryptographic ProtectionEncryption is a common Article 32 measure when confidentiality risk justifies it.
Recommendation — Perform a risk assessment to drive control selection and prioritisation. Use approved cryptography where confidentiality risk makes it proportionate.
ISO/IEC 27001:2022A.5.15 — Access controlAccess restrictions are a core organisational measure when processing risk requires bounded access.
A.8.13 — Information backupBackup and recovery are relevant where availability and loss tolerance affect the measure choice.
Recommendation — Define and enforce access rules that match the sensitivity of the processing. Implement backups and test recovery so availability risk is actually reduced.

Practitioner Guidance

What to prioritise: Start with a short, explicit risk statement for each processing activity, then map controls to the specific failure modes that matter most. If the measure does not reduce a realistic confidentiality, integrity, or availability risk, it is probably not the right Article 32 control to defend.

What to verify: Before trusting a chosen safeguard, confirm that it is actually operating in the environment, not just described in policy. Verify access boundaries, logging coverage, backup restore testing, and review cadence, because an untested control is often only a documentation artifact.

Practitioner takeaway: Article 32 is best treated as a living proportionality decision, not a one-time compliance label, so the real test is whether the safeguard remains justified as the processing context and threat landscape change.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org