GDPR Article 32 Security Assessment
An independent assessment of the technical and organisational measures protecting personal data, mapped clause by clause to Article 32, producing the regular-testing evidence a regulator or a customer auditor asks for first.
Report in three weeks. $4,900 fixed, pay after you review it.

Why Companies Commission an Article 32 Assessment
A breach happened and the regulator asked for evidence
The first request after a notification is not for the incident report. It is for proof that the measures were appropriate to the risk before the incident and that they were regularly tested. Every headline Bulgarian fine, the NRA at BGN 5.1 million, DSK Bank and Bulgarian Posts at BGN 1 million each, was an Article 32 case.
A customer is exercising its Article 28 audit right
Controllers must verify their processors, and the EDPB said in October 2024 that the duty runs down the whole sub-processor chain. Sales teams are now receiving audit questionnaires that a SOC 2 report does not fully answer, because the question is about GDPR Article 32, not about trust services criteria.
The policy exists, the test does not
Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of the measures. A lawyer or DPO can write the policy. Only a technical assessment in the live systems proves the measures work, and most companies have never commissioned one.


What the Assessment Covers
Article 32 is short and the assessment follows its structure exactly, so the report reads the way the regulation reads. Each sub-paragraph becomes a section with the controls examined, the evidence collected and the gaps found, graded by the risk to the people whose data is at stake rather than by a generic severity scale.



Independence Is the Whole Point
An assessment of security measures written by the provider that designed and runs them is a self-assessment with a logo on it. A supervisory authority will ask who verified the measures, and the answer has to be someone with no stake in the result.
We do not manage your infrastructure, we do not resell products, and we never hold the DPO seat and the assessor role for the same client, because Article 38(6) forbids the DPO from shaping the measures the DPO is supposed to monitor. If you already use our external DPO service, we will point you to a second assessor rather than compromise either role.
Every assessment is performed personally by a CISSP with 200+ security assessments across 14 countries since 2013, and the independence statement is printed in the report.
Who Needs It
Compared With the Usual Review
| Atlant Security | Typical review | |
|---|---|---|
| Evidence | Controls verified in the systems themselves | A document review of the security policy |
| Mapping | Every finding tied to an Article 32 sub-paragraph | A generic security checklist with GDPR in the title |
| Independence | Not your MSP, not the team that built the controls, and never your DPO | The IT provider assessing its own work |
| Usable afterwards | Attestation letter and evidence file for customers and the DPA | A PDF nobody can share |
| Pricing | Fixed, published, pay after you review the report | Day rates and an open-ended scope |
How the Assessment Works
Scoping and data-flow map
Where personal data lives, moves and leaves: systems, cloud services, processors and the people with access. This becomes the map the assessment follows and the map you keep.
Technical assessment in the live systems
Identity, endpoints, servers, cloud consoles, email, backups, encryption and logging examined directly, with configuration evidence, not screenshots supplied by the team that runs them.
Report mapped to Article 32
Each finding tied to the sub-paragraph it affects, graded by risk to data subjects, with the fix, the owner and the effort. Written so a supervisory authority or a customer auditor can read it without interpretation.
Attestation and re-test
Critical findings re-tested after remediation, then an attestation letter you can hand to customers, insurers and the regulator, dated and scoped.


Pricing
Fixed prices, scoped in writing, and you pay after you have reviewed the report.
Article 32 Security Assessment
One legal entity, all systems processing personal data, two to three weeks.
- Data-flow map of personal data
- Technical assessment in the live systems
- Report mapped to every Article 32 sub-paragraph
- Graded gap list with owners and effort
- Re-test of critical findings
- Attestation letter and evidence file
Article 32 Programme
The assessment plus the processor and breach side, kept current for a year.
- Everything in the assessment
- Audits of up to five processors on your behalf
- Mid-year re-test and attestation refresh
- 72-hour breach notification readiness and drill
- Customer audit questionnaire support
- Quarterly check-in on changes and new vendors
Have the Evidence Before Anyone Asks for It
A free scoping call tells you what the assessment would cover for your systems and what it will not. Three weeks later you hold the report and the attestation.
Book the Scoping Call