Article 32: Security of processing

Article 32.01

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the...

Article 32.02

In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal...

Article 32.03

Adherence to an approved code of conduct as referred to in  Article 40  or an approved certification mechanism as referred to in  Article 42  may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of ...

Article 32.04

The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or...