GDPR Article 32 and VAPT: Building a Defensible Security Program
August 10, 2026
GDPR Article 32 requires controllers and processors to implement "appropriate technical and organisational measures" to ensure a level of security appropriate to the risk of processing. The article is deliberately technology-neutral, leaving organisations to determine what "appropriate" means in their specific context — a flexibility that produces both operational latitude and enforcement uncertainty. VAPT evidence has emerged as one of the more defensible forms of documentation that appropriate technical measures were both implemented and validated. This document describes how VAPT programmes support Article 32 compliance and defence against enforcement actions.
The Structure of Article 32 Requirements
Article 32(1) enumerates specific measures that are "in particular" appropriate — pseudonymisation and encryption, ensuring confidentiality, integrity, availability and resilience of processing systems, ability to restore availability and access after incidents, and regular testing of the effectiveness of technical and organisational measures. The last enumerated measure — regular testing — is where VAPT evidence directly satisfies an explicit Article 32 requirement rather than serving as evidence of general due diligence.
Article 32(2) requires the measures to consider the state of the art, implementation cost, and the nature, scope, context, and purposes of processing along with the risk of varying likelihood and severity for the rights and freedoms of natural persons. This risk-based framing means that appropriate measures for one organisation differ from appropriate measures for another; VAPT programmes should be scaled to the risk profile of the specific processing rather than to a generic reference configuration.
Article 32(4) extends the technical measures requirement to processors — organisations that process personal data on behalf of controllers. Processors have direct Article 32 obligations independent of any contractual flow-down from the controller. This provision has been widely under-appreciated by processors, particularly SaaS providers and technology vendors, who sometimes treat GDPR obligations as flowing entirely through contracts. Direct regulatory liability has emerged as an increasing enforcement pattern.
DPIA Input and Article 35 Requirements
Article 35 requires Data Protection Impact Assessments (DPIAs) for processing operations that are likely to result in high risk to the rights and freedoms of natural persons. Large-scale processing of sensitive categories, systematic monitoring, and use of new technologies frequently triggers DPIA requirements. DPIAs require technical risk evidence to substantiate their risk assessment — VAPT provides exactly this evidence in a form Data Protection Authorities recognise.
A defensive DPIA structure incorporates VAPT findings as the technical risk assessment layer. Vulnerabilities identified by VAPT translate into risk scenarios in the DPIA — how a specific vulnerability could affect data subject rights, what the likelihood and severity of the impact would be, and what mitigations reduce the residual risk to acceptable levels. Reports that connect specific VAPT findings to specific DPIA risk scenarios produce stronger DPIAs than reports that reference VAPT results generically.
DPIAs are living documents that require periodic review. Continuous VAPT evidence provides the input for periodic DPIA updates — new findings inform new risk scenarios, remediated findings reduce risk quantification, and changes in processing scope trigger DPIA reviews that can draw on updated VAPT evidence immediately. Organisations that treat DPIAs as one-time exercises frequently find their DPIAs outdated by the time enforcement questions arise.
Processor Compliance and Data Processing Agreements
Data Processing Agreements (DPAs) between controllers and processors typically include specific security requirements that processors must satisfy. VAPT evidence has become a common DPA requirement — controllers require processors to conduct periodic VAPT and share the results or attestation of the results. Processors that can produce standardised VAPT evidence packages accelerate their sales cycles substantially compared to processors that assemble VAPT evidence ad-hoc for each customer request.
The specific evidence controllers accept varies. Enterprise controllers typically require detailed VAPT reports under confidentiality agreements. Mid-market controllers frequently accept summary attestations that describe the VAPT programme without exposing detailed findings. Some controllers accept SOC 2 or ISO 27001 certification as proxy evidence for VAPT since both frameworks require or imply regular security testing. Processors should structure their evidence programmes to satisfy the range of controller expectations they encounter.
Sub-processor management under DPAs requires similar VAPT evidence flowing through the processor chain. Processors that engage sub-processors (cloud infrastructure providers, sub-vendors for specific functions) must ensure their sub-processors satisfy equivalent security requirements. VAPT of the integrations between processor and sub-processor, plus review of sub-processor VAPT evidence, together satisfy the sub-processor security oversight obligation. The evidence should be organised to demonstrate the sub-processor management process, not just the specific sub-processor status.
Cross-Border Transfer Supplementary Measures
Following the Schrems II decision, cross-border transfers of personal data from the EU to third countries require supplementary measures beyond Standard Contractual Clauses (SCCs) to ensure the data receives essentially equivalent protection. The European Data Protection Board's recommendations enumerate technical measures — including strong encryption in transit and at rest, pseudonymisation, and access controls — that support the supplementary measures analysis.
VAPT evidence validates that these supplementary technical measures are effectively implemented. A transfer impact assessment that describes encryption and access controls as supplementary measures without evidence they are effectively implemented is weaker than one supported by VAPT findings showing the controls hold under adversarial testing. Organisations conducting significant cross-border transfers should ensure their VAPT programme explicitly covers the systems and controls supporting supplementary measures.
The 2023 EU-US Data Privacy Framework adds a specific transfer mechanism for US recipients, but transfers to other third countries still require SCC-based analysis with supplementary measures. Organisations with global operations should not assume the Privacy Framework eliminates supplementary measures obligations broadly — it addresses only US transfers under specific conditions. VAPT programmes should continue to support supplementary measures analysis for transfers to jurisdictions without adequacy decisions.
Enforcement Defence and Fine Mitigation
Article 83(2) enumerates factors Data Protection Authorities consider when calculating administrative fines. Factor (d) — the degree of responsibility of the controller or processor taking into account technical and organisational measures — is where documented VAPT evidence directly supports fine mitigation. Organisations that can demonstrate systematic security testing, timely identification of vulnerabilities, and effective remediation processes present a substantially better factor (d) position than organisations without such evidence.
Enforcement decisions in recent years have specifically cited the absence of regular security testing as an aggravating factor when fines were calculated. Conversely, organisations with mature VAPT programmes have received reduced fines even when significant incidents occurred, with authorities acknowledging that no security programme prevents all incidents but that mature programmes demonstrate the due diligence Article 32 requires. The evidence quality — not just the existence of VAPT — matters for this argument.
The evidence should demonstrate not just that VAPT was conducted but that the programme was operated as a security improvement mechanism, not as a compliance ceremony. Findings identified and closed, remediation timelines aligned to severity, and evolution of the programme in response to identified gaps all support the mature-programme argument. Organisations that produce VAPT reports without corresponding remediation evidence occasionally have this cited against them in enforcement — the finding was identified but not addressed, which is worse than not testing at all.
Building the Programme
A defensible GDPR-aligned VAPT programme includes continuous VAPT coverage of systems processing personal data, periodic deep-dive assessments of high-risk processing, integration of VAPT findings into DPIA workflows, DPA-ready evidence packages for controller and processor relationships, and structured retention of VAPT evidence to support future enforcement inquiries. Each component addresses a specific Article 32 or related regulatory concern; together they produce the evidence base that supports both operational security and regulatory defensibility.
The programme should also include specific processes for handling personal data during VAPT itself. Testers should operate under confidentiality agreements that satisfy processor obligations for the VAPT vendor. Test data should be synthesised or anonymised where possible. Any personal data observed during testing should be redacted from reports. These processes prevent VAPT itself from becoming a compliance concern under Article 32.
For organisations subject to multiple data protection regimes — GDPR, UK GDPR, Swiss FADP, and various national laws inspired by GDPR — a single well-structured VAPT programme typically satisfies the security testing expectations of all applicable regimes. The specific technical measures Article 32 requires are functionally equivalent to the technical measures required by UK GDPR, Swiss FADP, and most GDPR-inspired frameworks. Organisations should structure their VAPT programme once and produce evidence packages tailored to each specific regulatory audience from the same underlying evidence base.