Security of Processing
Security of processing is the requirement to protect personal data by putting in place suitable technical and organisational measures. In practice this means steps such as securing systems and workstations to keep data confidential and available, so that personal data is not lost, altered, or accessed by people who should not see it. The exact measures expected depend on the circumstances and are assessed against the level of risk involved.
Security of processing refers to the obligation, addressed in Article 32 of the GDPR (and correspondingly under the UK GDPR), to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The obligation applies to both controllers and processors and is risk-based rather than prescriptive: measures should reflect the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of risks to individuals. Recognised objectives include ensuring the ongoing confidentiality, integrity, availability, and resilience of processing systems and services, and the ability to restore access to personal data in a timely manner following an incident. Practical examples cited in regulatory guidance include measures such as firewalls, anti-virus software, and tools to block access to malicious sites, though appropriate measures must be determined case by case through assessment. This entry describes the general framework; specific expectations may evolve with guidance and technology, and readers should verify requirements against the current official text and applicable national implementing law.
Why it matters
Security of processing sits at the heart of data protection compliance because it operationalises the principle that personal data must be handled securely. Without appropriate technical and organisational measures, other obligations, such as lawfulness of processing or respecting individual rights, can be undermined by unauthorised access, loss, or alteration of data. The obligation applies to both controllers and processors, meaning responsibility for security is shared across the processing chain and cannot simply be delegated away.
Because the requirement is risk-based rather than prescriptive, organisations must actively assess what is appropriate in their own context. This matters for accountability: a measure that is adequate for a low-risk, small-scale processing activity may fall short where processing involves large volumes of data or heightened risks to individuals. Regulators generally expect organisations to be able to demonstrate the reasoning behind the measures they have chosen, rather than to point to a fixed checklist.
The standard is also dynamic. Because appropriate measures reflect the state of the art and evolving threats, what is considered sufficient can change over time and may diverge as guidance and technology develop. Organisations should therefore treat security of processing as an ongoing obligation subject to periodic review, and verify their approach against the current official text and applicable national implementing law rather than relying on a single snapshot.
Who it's relevant to
Inside Security of Processing
Common questions
Answers to the questions practitioners most commonly ask about Security of Processing.