ClearPenTest

European Union · General Data Protection Regulation (EU) 2016/679

Does GDPR require a penetration test?

GDPR is the European Union's data protection regulation. Its security obligation is short, outcome-based, and explicitly asks for regular testing of the measures an organization relies on.

Testing expectedArticle 32(1)(d)

The short answer

GDPR does not name penetration testing, but Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of processing. Regular security testing is the ordinary way to evidence that process.

Who it applies to

Any organization processing the personal data of people in the EU, regardless of where the organization itself is established.

In detail

Article 32 sets the security obligation and is deliberately risk-based: measures must be appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing. It gives examples including pseudonymisation, encryption, and the ability to restore availability after an incident.

Subparagraph (d) is the testing hook. A process for regularly testing, assessing and evaluating effectiveness is a requirement in its own right, separate from having the measures at all. An organization that has controls but never checks whether they work has not met 32(1)(d).

GDPR interacts with the other frameworks here more than it competes with them. An ISO 27001 certification is commonly used to demonstrate appropriate measures under Article 32, and Article 42 contemplates certification mechanisms as a way of demonstrating compliance.

What to have in scope

  • Systems processing personal data of people in the EU
  • Access controls, encryption in transit and at rest, and data isolation between customers
  • Evidence of a repeating test cycle, since 32(1)(d) asks for a process rather than an event
  • Findings linked to the record of processing activities and the risk assessment

Questions people ask

Does GDPR require penetration testing?

Not by name. Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures. Penetration testing is the usual way to evidence that process, but the regulation describes an outcome rather than a technique.

Does ISO 27001 certification satisfy GDPR?

It does not make an organization GDPR compliant, because GDPR covers lawful basis, data subject rights and transfers as well as security. It is commonly used as evidence that security measures are appropriate under Article 32.

This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.

Get a scoped price without a discovery call

Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.