Cybersecurity All vCISO

Blog space

GDPR and Cybersecurity – what Article 32 actually requires from your security controls

In this article you will learn:

  • How GDPR connects with cybersecurity
  • When a data breach must be reported and how the 72-hour rule works
  • How ISO 27001 supports GDPR compliance
GDPR and Cybersecurity

Updated: 4 August 2026

What does GDPR require from cybersecurity? Article 32 of GDPR requires controllers and processors to implement “appropriate technical and organisational measures” to protect personal data – including encryption, resilience, the ability to restore availability quickly after an incident, and a process for regularly testing and evaluating the effectiveness of those measures. GDPR does not treat data protection and information security as separate disciplines. Article 33 starts a 72-hour notification clock when a personal data breach is identified.

The ICO fined British Airways £20 million in Oct 2020 and Marriott International £18.4 million for inadequate security around personal data – these were cybersecurity failures with privacy consequences, not the other way around (ICO Annual Report 2020/21).

GDPR and cybersecurity requirements – at a glance:

  1. GDPR Article 32 requires organisations to implement appropriate technical and organisational measures proportionate to the risk – including pseudonymisation, encryption, confidentiality, integrity, availability, resilience and regular effectiveness testing.
  2. The 72-hour notification clock under Article 33 starts when the organisation becomes aware that a personal data breach has occurred – not when the forensic investigation is complete.
  3. A personal data breach includes hacks, misdirected emails, ransomware encrypting personal data, former employees accessing records, cloud misconfigurations and data corruption – not only dramatic external intrusions.
  4. The ICO fined British Airways £20 million (Oct 2020) and Marriott International £18.4 million (Oct 2020) – both cases were cybersecurity control failures with privacy consequences.
  5. Meta received a EUR 1.2 billion fine from the Irish DPC in May 2023 – the largest GDPR fine to date – demonstrating that data-protection failures can escalate to strategic financial risk.
  6. DLA Piper GDPR Fines and Data Breach Survey 2024: EUR 1.78 billion in fines issued by European data protection authorities in the prior year – enforcement has become normalised.
  7. Patronusec helps organisations align legal and technical teams: risk assessment, technical controls, testing, audit evidence and practical decision support for breach readiness.


How does Article 32 connect GDPR and cybersecurity in practice?

Article 32 is the centre of gravity for cybersecurity under GDPR. It says controllers and processors must implement technical and organisational measures appropriate to the risk – taking into account the state of the art, the cost of implementation, and the nature and purposes of processing. It explicitly names examples: pseudonymisation, encryption, the ability to ensure ongoing confidentiality, integrity, availability and resilience, the ability to restore availability and access in a timely manner, and a process for regularly testing and evaluating the effectiveness of those measures (GDPR Article 32).

GDPR Article 32 themeWhat it means in practiceTypical security controls
Pseudonymisation and encryptionReduce the link between data and an identifiable person; protect data at rest and in transitDatabase field tokenisation, encrypted backups, full-disk encryption, TLS, key management
ConfidentialityOnly authorised people and systems should access personal dataIAM, MFA, role-based access, joiners/movers/leavers controls, logging, privileged access review
IntegrityData should not be improperly altered or silently corruptedChange management, checksums, versioning, separation of duties, audit trails
Availability and resilienceSystems processing personal data must remain usable and recoverableBackups, BCM, disaster recovery, redundant systems, ransomware-resistant restore testing
Ability to restore access quicklyAfter an incident, you must recover operations and data in a timely mannerDocumented recovery procedures, tested backup restores, incident runbooks, RTOs
Regular testing and evaluationSecurity measures must be reviewed, not merely installedVulnerability scanning, penetration testing, access reviews, phishing exercises, internal audits

The final requirement is the most operationally revealing: a process for regularly testing, assessing and evaluating the effectiveness of measures. Article 32 does not ask whether you bought security tools – it asks whether you review whether they work.

Patronusec Insight: The most common error we observe is treating GDPR Article 32 as a policy checklist rather than an operational requirement. An encryption policy without evidence that encryption is actually applied does not satisfy Article 32. In engagements delivered through vCISO, we build a map of technical controls to Article 32 requirements and provide a testing-effectiveness schedule – so the organisation has ready evidence for a regulator or auditor query.

When does the 72-hour GDPR breach notification clock start?

Article 33 requires the controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it – unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (GDPR Article 33).

The most important practical point: the 72-hour period starts when the organisation becomes aware that a personal data breach has occurred – not when the internal investigation is perfectly complete. EDPB guidance is clear that notification can be phased if not all information is immediately available – Article 33 itself allows information to be provided in phases. Waiting for perfect certainty is one of the easiest ways to drift into late notification (EDPB Guidelines 9/2022).

Even when a breach does not require external notification, you must still maintain a defensible internal incident record: detection, triage, decision-making, legal assessment, technical containment and lessons learned. Regulators often learn as much from the quality of your incident documentation as from the incident itself.


Not sure whether your incident response plan supports the 72-hour GDPR notification requirement?

Patronusec reviews whether your IR procedures enable timely notification, identifies evidence gaps and supports building documentation that withstands a regulator query. After a free scope-assessment call we deliver a written readiness assessment.

Book a breach readiness review


What counts as a personal data breach under GDPR – more than you might think?

Many executives still imagine a reportable breach as a dramatic external hack. GDPR’s definition is far broader. A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed (GDPR Article 4(12)).

In plain terms: a personal data breach is not only a hack. It includes accidental disclosure, loss of access, unauthorised internal access, misdirected emails, ransomware encrypting personal data, deleted records, corrupted files or any security failure that compromises the confidentiality, integrity or availability of personal data.

Your incident response process should therefore not ask only “Was this a cyberattack?” It should ask “Did this security event affect the confidentiality, integrity or availability of personal data?” If the answer may be yes, legal and security should already be in the same conversation.

What major GDPR fines have been imposed for cybersecurity failures?

British Airways, Oct 2020.
The ICO fined BA £20 million after attackers diverted users from the airline’s website to a fraudulent site in 2018, compromising personal and financial data of more than 400,000 customers. The ICO stated that BA was processing significant amounts of personal data without appropriate security measures and did not detect the cyberattack for more than two months (ICO Annual Report 2020/21).

Marriott International, Oct 2020.
The ICO fined Marriott £18.4 million after finding it had failed to implement appropriate technical or organisational measures to protect the personal data of approximately 339 million guest records globally (ICO Annual Report 2020/21).

Meta, May 2023.
The Irish DPC imposed a EUR 1.2 billion fine on Meta Ireland – the largest GDPR fine to date. The case demonstrates that data-protection failures tied to technical and organisational safeguards can escalate to strategic financial risk quickly (Irish DPC, 22 May 2023).

Patronusec Insight: A correct Article 32 response is not a list of policies – it is proof of control operation. Organisations with an active ISO 27001 programme have the ready foundations: a control inventory, risk logic and evidence discipline that Article 32 presupposes. However, ISO 27001 does not replace GDPR – it adds the technical-operational layer that typically shortens the GDPR compliance project by an estimated 40-60%.

FAQ – GDPR and Security

Does GDPR require companies to have cybersecurity measures?

Yes. GDPR Article 32 requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk – including encryption, resilience, recovery capability and regular testing of the effectiveness of measures.

What is a personal data breach under GDPR?

A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It includes hacks, misdirected emails, ransomware, unauthorised internal access and data corruption (GDPR Article 4(12)).

How long do you have to report a data breach under GDPR?

Under Article 33, the controller must notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a reportable personal data breach. Not every breach must be reported externally, but every breach must be assessed and documented internally.

What are the GDPR fines for inadequate cybersecurity?

Inadequate security measures under Articles 32, 33 and 34 can fall into the lower penalty tier of up to EUR 10 million or 2% of worldwide annual turnover, whichever is higher. More fundamental infringements can reach EUR 20 million or 4% (GDPR Article 83).

How does ISO 27001 support GDPR compliance?

ISO 27001 does not replace GDPR, but provides a managed control framework, risk assessment process, internal audit cycle and evidence model that strongly support Article 32 and breach-readiness work. Organisations with ISO 27001 typically complete GDPR technical assessments faster because they already have the control inventory and evidence disciplines Article 32 expects.

How much does a GDPR Article 32 compliance review cost with Patronusec?

The cost depends on the scope of data processing, environment complexity and existing documentation. After a free scope-assessment call we provide a fixed-price proposal. For organisations holding ISO 27001, we offer dedicated Article 32 mapping against existing ISMS controls.


GDPR and cybersecurity alignment – free consultation

Patronusec helps organisations align legal and technical teams: risk assessment, technical controls, testing, audit evidence and practical decision support for breach readiness. If your legal and IT teams are still operating on parallel tracks, now is the right time to bring them into one programme.

In a free 30-minute consultation we will help you:

  • Assess whether your current technical controls meet GDPR Article 32 requirements
  • Review whether your IR procedures enable timely notification under the 72-hour clock
  • Identify evidence gaps that could harm your position in a regulatory investigation
  • Plan ISO 27001 mapping to GDPR requirements for maximum efficiency

Book a GDPR/cybersecurity consultation | ISO 27001 | NIS2 | vCISO | Penetration testing

Don't buy a pig in a poke -
request a free consultation and check how we can assist you.

Free consultation
Contact form

Use the contact form or contact us directly.

Patronusec Sp z o. o.

Head Office:
ul. Święty Marcin 29/8
61-806 Poznań, Polska

KRS: 0001039087
REGON: 525433988
NIP: 7831881739
D-U-N-S: 989454390
LEI: 259400NAR8ZOX1O66C64

To top