GDPR Article 32 / Security of processing

GDPR Article 32 Security Assessment

An independent assessment of the technical and organisational measures protecting personal data, mapped clause by clause to Article 32, producing the regular-testing evidence a regulator or a customer auditor asks for first.

Report in three weeks. $4,900 fixed, pay after you review it.

Verified in the live systemsAttestation letter includedAnswers Article 28 customer audits
GDPR Article 32 security of processing assessment by Atlant Security

Why Companies Commission an Article 32 Assessment

A breach happened and the regulator asked for evidence

The first request after a notification is not for the incident report. It is for proof that the measures were appropriate to the risk before the incident and that they were regularly tested. Every headline Bulgarian fine, the NRA at BGN 5.1 million, DSK Bank and Bulgarian Posts at BGN 1 million each, was an Article 32 case.

A customer is exercising its Article 28 audit right

Controllers must verify their processors, and the EDPB said in October 2024 that the duty runs down the whole sub-processor chain. Sales teams are now receiving audit questionnaires that a SOC 2 report does not fully answer, because the question is about GDPR Article 32, not about trust services criteria.

The policy exists, the test does not

Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of the measures. A lawyer or DPO can write the policy. Only a technical assessment in the live systems proves the measures work, and most companies have never commissioned one.

Bulgarian GDPR fines under Article 32: NRA BGN 5.1 million, DSK Bank and Bulgarian Posts BGN 1 million each
Article 32(1)(d) requires a process for regularly testing the effectiveness of security measures

What the Assessment Covers

Article 32 is short and the assessment follows its structure exactly, so the report reads the way the regulation reads. Each sub-paragraph becomes a section with the controls examined, the evidence collected and the gaps found, graded by the risk to the people whose data is at stake rather than by a generic severity scale.

32(1)(a) Encryption and pseudonymisation
Data at rest and in transit, key management, where pseudonymisation is applied and where it should be
32(1)(b) Confidentiality, integrity, availability, resilience
Identity and access, MFA, privileged accounts, endpoint protection, patching, cloud configuration, logging
32(1)(c) Restore access after an incident
Backup coverage, tested restores, recovery time against what the business needs
32(1)(d) Regular testing process
Whether a testing cycle exists, what it covers, and the evidence it produces
32(2) Risk-based selection
The risk assessment that justifies the measures, and the gaps between the two
28 and 32(4) Processors and staff
Processor contracts, sub-processor visibility, and whether staff can only act on instruction
The requirements of GDPR Article 32 sub-paragraphs (a) to (d)
Scope of the GDPR Article 32 security assessment across identity, endpoints, cloud, backups, network and processors
Independence rule: the Article 32 assessor is never the MSP, the control owner or the DPO

Independence Is the Whole Point

An assessment of security measures written by the provider that designed and runs them is a self-assessment with a logo on it. A supervisory authority will ask who verified the measures, and the answer has to be someone with no stake in the result.

We do not manage your infrastructure, we do not resell products, and we never hold the DPO seat and the assessor role for the same client, because Article 38(6) forbids the DPO from shaping the measures the DPO is supposed to monitor. If you already use our external DPO service, we will point you to a second assessor rather than compromise either role.

Every assessment is performed personally by a CISSP with 200+ security assessments across 14 countries since 2013, and the independence statement is printed in the report.

Who Needs It

SaaS processors answering customer audits and DPA questionnaires
Fintech and payment firms where a breach means a supervisor and a DPA at once
Healthtech and any company holding special-category data
E-commerce and marketing businesses processing customer data at scale
Any Bulgarian or EU company that wants the evidence file before it is asked for it

Compared With the Usual Review

Atlant SecurityTypical review
EvidenceControls verified in the systems themselvesA document review of the security policy
MappingEvery finding tied to an Article 32 sub-paragraphA generic security checklist with GDPR in the title
IndependenceNot your MSP, not the team that built the controls, and never your DPOThe IT provider assessing its own work
Usable afterwardsAttestation letter and evidence file for customers and the DPAA PDF nobody can share
PricingFixed, published, pay after you review the reportDay rates and an open-ended scope

How the Assessment Works

1

Scoping and data-flow map

Where personal data lives, moves and leaves: systems, cloud services, processors and the people with access. This becomes the map the assessment follows and the map you keep.

2

Technical assessment in the live systems

Identity, endpoints, servers, cloud consoles, email, backups, encryption and logging examined directly, with configuration evidence, not screenshots supplied by the team that runs them.

3

Report mapped to Article 32

Each finding tied to the sub-paragraph it affects, graded by risk to data subjects, with the fix, the owner and the effort. Written so a supervisory authority or a customer auditor can read it without interpretation.

4

Attestation and re-test

Critical findings re-tested after remediation, then an attestation letter you can hand to customers, insurers and the regulator, dated and scoped.

The four step GDPR Article 32 assessment process
What the Article 32 assessment delivers: report, gap list, attestation letter, evidence file

Pricing

Fixed prices, scoped in writing, and you pay after you have reviewed the report.

Most common

Article 32 Security Assessment

One legal entity, all systems processing personal data, two to three weeks.

$4,900fixed
  • Data-flow map of personal data
  • Technical assessment in the live systems
  • Report mapped to every Article 32 sub-paragraph
  • Graded gap list with owners and effort
  • Re-test of critical findings
  • Attestation letter and evidence file
Book Free Scoping Call

Article 32 Programme

The assessment plus the processor and breach side, kept current for a year.

$8,900per year
  • Everything in the assessment
  • Audits of up to five processors on your behalf
  • Mid-year re-test and attestation refresh
  • 72-hour breach notification readiness and drill
  • Customer audit questionnaire support
  • Quarterly check-in on changes and new vendors
Book Free Scoping Call

Have the Evidence Before Anyone Asks for It

A free scoping call tells you what the assessment would cover for your systems and what it will not. Three weeks later you hold the report and the attestation.

Book the Scoping Call

Schedule Your Free Scoping Call

GDPR Article 32 FAQ

What does GDPR Article 32 actually require?
Technical and organisational measures appropriate to the risk, including as appropriate pseudonymisation and encryption, the ability to ensure ongoing confidentiality, integrity, availability and resilience, the ability to restore availability and access after an incident, and a process for regularly testing, assessing and evaluating the effectiveness of those measures. The measures must be chosen against an assessment of the risk to the people whose data you process, not against a generic standard.
Is an external Article 32 assessment mandatory?
The regulation does not name an external assessor. It requires the regular testing process to exist and to produce evidence. In practice supervisory authorities treat an independent assessment or penetration test as the evidence, and a controller assessing its own measures rarely survives the question of who verified them. The assessment is the cheapest way to have the answer before the question is asked.
How often should it be repeated?
Annually is the accepted baseline, and after any significant change: a new platform, a migration, a merger or an incident. Bulgarian and EU regulators do not prescribe a frequency, which is why the report states the period it covers and the date by which the next assessment is due.
How is this different from a penetration test or ISO 27001?
A penetration test answers whether an attacker can get in. ISO 27001 answers whether a management system exists. Article 32 asks a narrower question: are the measures protecting personal data appropriate to the risk, and are they tested. The assessment uses penetration testing and control review as inputs and produces an answer in the language of the regulation, which is what a DPA or a customer auditor reads.
What is in the report?
A scope and data-flow map, a risk assessment summary, findings mapped to each Article 32 sub-paragraph and graded by risk to data subjects, remediation steps with owners and effort, evidence references for every conclusion, and an attestation letter once critical findings are closed. The evidence file is structured so it can be produced to the Commission for Personal Data Protection or any other authority as it stands.
Can we use it to answer customer Article 28 audits?
Yes. That is the second reason companies commission it. The attestation letter and the evidence file answer most controller audit questionnaires directly, and where a customer insists on its own audit, the file cuts the time it takes from weeks to days. Processors that receive many requests usually move to the annual programme so the answer is always current.
Why will you not do this if you are also our DPO?
Article 38(6) prohibits the DPO from holding a role that determines the means of processing or creates a conflict of interest. Assessing and shaping the security measures is such a role. We therefore hold either the external DPO seat or the Article 32 assessor role for a client, never both, and we say so in the engagement letter.
How much does it cost?
The Article 32 Security Assessment is $4,900 fixed for a single legal entity, delivered in two to three weeks, and you pay after you have reviewed the report. The Article 32 Programme is $8,900 per year and adds audits of up to five processors on your behalf, a mid-year re-test, breach notification readiness and the attestation refreshed for the year. Groups and multi-entity structures are quoted in writing before we start.

Related Services