← Back to list

GDPR Series — Chapter 4 (Section 2): Security of Personal Data

Once you start handling personal data, you take on a big responsibility — keeping it secure. GDPR’s Chapter 4, Section 2 emphasizes that…

Arzoo Parween · 2025-04-11 10:48 · 0 claps · 3.2 min read
#gdpr #data-security-controls #breach-notification #data-breach-notification #personal-data-protection
Open on Medium ↗

GDPR Series — Chapter 4 (Section 2): Security of Personal Data

Once you start handling personal data, you take on a big responsibility — keeping it secure. GDPR’s Chapter 4, Section 2 emphasizes that responsibility through clear obligations for organizations around data security and how to respond when things go wrong.

This section includes three crucial articles:

  • Article 32: Security of processing
  • Article 33: Notification of a personal data breach to the supervisory authority
  • Article 34: Communication of a personal data breach to the data subject

Let’s walk through each one and see what it really means in practice.

Article 32 — Security of Processing

This article is GDPR’s way of saying: “Protect personal data like it actually matters.” And it does — because if it gets exposed, the impact on individuals (and your organization) can be serious.

What it Requires:

Organizations must implement appropriate technical and organizational measures to ensure a level of security that matches the risk.

Examples of security measures:

  • Encrypting or pseudonymizing personal data.
  • Ensuring confidentiality, integrity, and availability of systems.
  • Being able to restore access quickly after an incident.
  • Regularly testing and reviewing your security setup.

What does “appropriate” mean?

There’s no one-size-fits-all. GDPR encourages a risk-based approach:

  • What kind of data are you dealing with?
  • How sensitive is it?
  • How big is your business?
  • How likely is a breach?

Example: An HR platform encrypts all user data, requires multi-factor authentication, and conducts quarterly security reviews. That’s a solid approach under Article 32.

Use this checklist to ensure your organization is taking appropriate technical and organizational measures to secure personal data:

🔐 Technical Measures

☑️ Encrypt personal data (at rest and in transit) ☑️ Apply pseudonymization or anonymization where possible ☑️ Use access controls and role-based permissions ☑️ Enforce strong password policies ☑️ Install and update firewalls, antivirus, and anti-malware tools ☑️ Patch and update systems regularly (OS, apps, databases) ☑️ Maintain secure, tested backups ☑️ Implement integrity checks for data modifications ☑️ Log and monitor access to personal data systems

🏢 Organizational Measures

☑️ Document and maintain privacy & security policies ☑️ Conduct staff training on GDPR and data security ☑️ Limit access to personal data on a need-to-know basis ☑️ Vet and contractually bind third-party processors (with DPAs) ☑️ Establish and test a data breach response plan ☑️ Perform regular data protection audits ☑️ Maintain up-to-date records of processing activities (Article 30)

🔁 Operational Resilience

☑️ Design systems to ensure confidentiality, integrity, and availability ☑️ Ensure the ability to restore data access quickly after an incident ☑️ Regularly test and evaluate security controls and procedures

Article 33 — Notification of a Personal Data Breach to the Supervisory Authority

Let’s face it: data breaches happen — even at well-prepared companies. The key is how you respond.

The Rule:

If a breach happens and it poses a risk to people’s rights and freedoms, you must report it to the supervisory authority within 72 hours of becoming aware.

Missed the deadline? You’ll need to explain why.

What to include in the breach notification:

  • What happened (type of breach, categories of data).
  • Number of people affected.
  • Consequences of the breach.
  • Actions taken or planned to address the breach.
  • Contact details for further information (e.g., your DPO).

Example: A law firm accidentally sends confidential client emails to the wrong recipient. They assess the risk, report the breach to their country’s data protection authority within 72 hours, and detail how it won’t happen again.

Article 34 — Communication of a Personal Data Breach to the Data Subject

Sometimes, a breach is serious enough that affected individuals need to be informed — quickly.

When to notify individuals:

If a breach is likely to result in a high risk to individuals (think identity theft, financial fraud, or emotional distress), you must inform them without undue delay.

What to include:

  • What happened.
  • What type of personal data was involved.
  • What consequences might arise.
  • What you’re doing to fix the situation.
  • Steps individuals can take to protect themselves.
  • Contact info for further support.

When notification isn’t required:

  • If the data was encrypted or otherwise unintelligible.
  • If you’ve taken steps that neutralize the risk.
  • If notifying everyone individually would take disproportionate effort (you can use a public notice instead).

Example: A fitness app discovers a breach where names, locations, and health data were accessed. Since the data was sensitive and unencrypted, they inform users immediately and provide tips for securing their accounts.

Final Thoughts

Security under GDPR isn’t a checklist — it’s a continuous process. Section 2 reminds us that:

  • Prevention is essential.
  • Preparation matters.
  • Transparency is non-negotiable when things go wrong.

If you handle personal data, Section 2 is your call to invest in real security, not just compliance theater. Because protecting people’s data means protecting their trust — and that’s good for everyone.

Up next, we’ll dive into Section 3: Data Protection Impact Assessment and Prior Consultation, where GDPR lays out how to build privacy into your planning from the very beginning.


메타데이터
post_id
fd52fec82c23
slug
gdpr-series-chapter-4-section-2-security-of-personal-data-fd52fec82c23
url
https://medium.com/@arzoo01/gdpr-series-chapter-4-section-2-security-of-personal-data-fd52fec82c23
canonical_url
https://medium.com/@arzoo01/gdpr-series-chapter-4-section-2-security-of-personal-data-fd52fec82c23
author_url
https://medium.com/@arzoo01
status
ok
fetched_at
2026-06-12 18:14:10