← GDPR · Security
Art.32 — Security of processing
Requirement
The controller and processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including pseudonymisation and encryption, resilience, restoration of availability, and a process for regularly testing the effectiveness of measures.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| NDPA 2023 | s.39 | Security, integrity and confidentiality | encryption-at-rest encryption-in-transit access-control backup |
| CCPA/CPRA | 1798.100(e) & 1798.150 | Reasonable security procedures | encryption-at-rest access-control |
| SOC 2 | CC6.1 | Logical access provisioning and restriction | access-control encryption-at-rest |
| SOC 2 | CC6.7 | Restriction of information transmission, movement and removal | encryption-in-transit encryption-at-rest |
| ISO 27001 | A.8.24 | Use of cryptography | encryption-at-rest encryption-in-transit |
| GLBA | 314.4(c)(3) | Encryption of customer information in transit and at rest | encryption-at-rest encryption-in-transit |
| SOC 2 | CC5.2 | Technology general controls | access-control |
| SOC 2 | CC6.2 | Registration and authorisation of new users | access-control |