Process for Regularly Testing and Evaluating
This is a requirement under data protection law that an organisation must have an ongoing way of checking whether its security measures actually work, rather than setting them up once and assuming they are effective. The idea is that security is tested and re-evaluated over time to confirm it still protects personal data. The law describes the outcome required but does not tell organisations exactly which testing methods to use.
Under Article 32 of the UK GDPR (mirrored in the EU GDPR), controllers and processors are generally required to implement a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures adopted to ensure the security of processing. According to ICO guidance, this is a specific obligation and not merely good practice. The Regulation is method-neutral: it does not prescribe a particular technique, frequency, or tool (for example, vulnerability assessments or penetration testing are commonly used approaches referenced in industry guidance, but are not mandated by the Article text). What constitutes an appropriate testing process is subject to assessment, typically calibrated to the state of the art, costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to individuals. This entry addresses the testing and evaluation limb of Article 32 specifically and does not restate the full scope of security obligations under that Article; readers should verify the precise wording and any applicable national derogations against the current official text.
Why it matters
Security measures degrade over time. A configuration that was appropriate when deployed can become inadequate as threats evolve, systems change, and new vulnerabilities emerge. The testing and evaluation requirement under Article 32 recognises this reality: it treats security not as a one-off implementation but as an ongoing state that must be actively verified. According to ICO guidance, this is a specific obligation rather than merely good practice, meaning an organisation that implements strong measures but never checks whether they still work may fall short of what the law expects.
From a compliance perspective, the requirement matters because it shifts the evidentiary burden. Being able to demonstrate a documented, repeated process of testing and evaluation supports accountability and helps show that security decisions are calibrated to current risk. Where a security incident occurs, the presence or absence of a meaningful testing regime is likely to be relevant to how a supervisory authority assesses whether appropriate technical and organisational measures were in place. It is important to note that no testing process guarantees compliance; the adequacy of any given approach is subject to assessment against the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to individuals.
The requirement is method-neutral, which is both a flexibility and a source of uncertainty. The Article text does not name a particular technique, frequency, or tool, so organisations must exercise judgement about what is proportionate to their risk profile. This means there is no single benchmark that definitively satisfies the obligation, and readers should be cautious about treating any vendor's proposed framework or a particular testing cadence as settled legal requirement rather than one reasonable interpretation.
Who it's relevant to
Inside Process for Regularly Testing and Evaluating
Common questions
Answers to the questions practitioners most commonly ask about Process for Regularly Testing and Evaluating.