Skip to main content
Category: Security & Breach Notification

State of the Art

Also known as: state-of-the-art
Simply put

State of the art refers to the highest level of general development in a device, technique, or field of science reached at a particular point in time. In a data protection context, it is a benchmark used to judge how advanced the security and privacy measures an organisation adopts should be, taking into account what is currently achievable. Because it reflects development at a given moment, what counts as state of the art evolves over time.

Formal definition

State of the art denotes the level of development of a device, procedure, process, technique, or science achieved at a particular time, representing the leading edge of what is generally available and technically feasible rather than purely experimental. As a general concept, it functions as a moving, time-dependent benchmark that must be reassessed as technology advances. Note: the evidence packet provided contains only general-language and unrelated sources; it does not include the GDPR text or official guidance, so the specific role of 'state of the art' as a factor in GDPR obligations (for example in relation to security of processing or data protection by design) is not established by this evidence and should be verified against the current official Regulation text and competent supervisory authority guidance before being relied upon in a compliance program.

Why it matters

In data protection, the phrase "state of the art" is significant because it establishes a moving benchmark rather than a fixed standard. An organisation cannot demonstrate that its safeguards are adequate simply by pointing to measures that were considered advanced in the past; the concept requires that measures be assessed against the highest level of general development reached at the relevant point in time. Because this level evolves as technology and techniques advance, a control that was defensible when implemented may need to be reassessed as newer, generally available approaches emerge.

The evidence available here draws only from general-language sources, which define "state of the art" as the highest level of development of a device, procedure, process, technique, or science achieved at a particular time. It does not include the GDPR text or supervisory authority guidance. As a result, the specific weight this concept carries within particular data protection obligations is not established by this evidence and should be confirmed against the current official Regulation text and competent regulator guidance before it is relied upon in a compliance program.

Because the benchmark is time-dependent, treating it as a one-off assessment risks leaving safeguards behind the leading edge of what is generally available. Organisations should generally treat the evaluation as recurring, revisiting whether adopted measures still reflect the current level of development rather than an earlier snapshot.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those responsible for oversight benefit from treating state of the art as a recurring, time-dependent assessment rather than a fixed determination. They should generally build periodic reviews into governance processes so that adopted safeguards continue to reflect the current level of general development. The specific role of this concept within particular obligations should be confirmed against the current official Regulation text and competent supervisory authority guidance.
Security and Engineering Teams
Engineers implementing technical measures need to distinguish between what is generally available and technically feasible and what remains purely experimental. Because the leading edge shifts as techniques develop, teams should reassess whether their controls still align with the prevailing level of development rather than relying on choices made at an earlier point in time.
Legal Advisers
Lawyers advising on the adequacy of measures should note that state of the art is a moving benchmark tied to a particular moment, which affects how defensibility is evaluated over time. Since the evidence here derives only from general-language sources and not the Regulation or official guidance, advisers should verify the precise legal function of the term against the current official text before relying on it.

Inside State of the Art

Reference to state of the art in the GDPR
The phrase appears in the GDPR most prominently in the provisions on security of processing and on data protection by design and by default, where it forms part of the factors a controller or processor must weigh when determining appropriate technical and organisational measures. Verify the precise article references against the current official text.
A relative and evolving standard
State of the art is not a fixed technical specification but a moving benchmark that reflects the level of technical development and available safeguards at a given point in time. What qualifies as state of the art generally shifts as technology, threats, and available measures evolve.
One factor among several
State of the art is typically balanced against other listed factors, such as the costs of implementation, the nature, scope, context and purposes of processing, and the risks to the rights and freedoms of individuals. It is not assessed in isolation and does not by itself dictate a single mandatory measure.
Distinct from the latest available technology
State of the art is generally understood to sit between what is merely the most cutting-edge technology and what is only common industry practice. It refers to established, proven and available methods rather than experimental or purely aspirational solutions, though the exact boundary is a matter of assessment.
Applies to both technical and organisational measures
The concept informs not only technical controls such as encryption or pseudonymisation but also organisational measures, insofar as available approaches to governance and process reflect current recognised practice.

Common questions

Answers to the questions practitioners most commonly ask about State of the Art.

Does 'state of the art' mean an organisation must always deploy the newest or most advanced technology available?
No. This is a common misconception. 'State of the art' does not require adopting the latest or most cutting-edge technology on the market. Under Article 32 (and echoed in Article 25 on data protection by design and by default), it functions as one factor to be weighed alongside the costs of implementation, the nature, scope, context and purposes of processing, and the risks to individuals. The concept generally refers to the recognised body of technical and organisational measures that are established, effective, and available in practice, rather than experimental or bleeding-edge solutions. What qualifies is context-dependent and subject to assessment, and the reader should verify current regulatory guidance, which can evolve over time.
Is 'state of the art' a fixed standard that, once met, guarantees compliance?
No. It is not a static benchmark and meeting it does not, by itself, guarantee compliance. The term is dynamic: what is regarded as state of the art typically shifts as technology, threats, and industry practice develop. It is also only one element of the overall risk-based assessment required under Articles 32 and 25, which must balance it against cost, risk, and the circumstances of the processing. Compliance is context and risk dependent, so treating a single point-in-time measure as permanently sufficient would misread the concept.
How should an organisation determine what counts as 'state of the art' for a given processing activity?
In most cases this is a documented, evidence-based assessment rather than a single lookup. Organisations typically consider recognised standards, published guidance from supervisory authorities and bodies such as ENISA, established industry practice, and available and effective measures relevant to the specific risk. Because the determination is contextual, it should be tied to the nature, scope, context, and purposes of the processing and the risks to individuals, and revisited as circumstances change. Where guidance diverges between regulators, note the divergence and reason from the applicable jurisdiction.
How often should the 'state of the art' assessment be reviewed?
Because the concept is dynamic, a review should generally be periodic and also triggered by relevant change, such as new threats, technological developments, updated regulatory guidance, or material changes to the processing. There is no single mandated interval stated for this in the Regulation text, so organisations typically align reviews with their broader security and data protection review cycles and document the rationale. Verify any specific timing expectations against current official guidance.
How does 'state of the art' interact with the cost of implementation in decision-making?
Articles 32 and 25 present state of the art and cost of implementation as factors to be balanced together, alongside the risk to individuals and the circumstances of processing. This generally means an organisation weighs what effective measures are available against what is proportionate to implement given the risk. Cost does not by itself justify omitting appropriate safeguards where risk is high, but the framework is a proportionality assessment rather than an absolute requirement to adopt every available measure. The outcome is context and risk dependent.
What should be documented to evidence that state of the art was considered?
It is generally advisable to record the measures considered, the reasoning for those selected and rejected, the risks identified, the sources or standards relied upon, and how state of the art was balanced against cost and risk. Such documentation typically supports the accountability principle and can help demonstrate that the assessment was made and kept under review. The precise form is not prescribed in the Regulation text, so organisations should align documentation with their governance practices and any applicable supervisory authority expectations.

Common misconceptions

State of the art means you must always deploy the newest or most advanced technology available.
State of the art is generally understood as a proven, available and recognised standard rather than the absolute latest innovation. It is also weighed against cost of implementation and the risks involved, so the most advanced option is not necessarily required in every case; the appropriate measure is subject to assessment.
State of the art is a fixed checklist that, once met, guarantees compliance.
The standard is relative and evolving, so a measure considered adequate at one time may no longer be sufficient later. Meeting it at a given moment does not by itself establish full compliance, which remains context and risk dependent and must be reviewed over time.
State of the art alone determines which security measures a controller must implement.
It is only one of several factors. Controllers and processors typically balance it against implementation costs and the nature, scope, context, purposes and risks of the processing when deciding on appropriate technical and organisational measures.

Best practices

Treat state of the art as a moving benchmark and reassess your technical and organisational measures periodically rather than relying on a one-time evaluation.
Document how you weighed state of the art against the other factors, including implementation costs and the risks to individuals, so your decisions are demonstrable and defensible.
Distinguish between proven, available measures and purely experimental technology, and generally anchor decisions to recognised and established approaches rather than the newest untested option.
Apply the concept to both technical controls and organisational processes, since state of the art can inform governance and procedures as well as tools.
Monitor evolving guidance from supervisory authorities and relevant standards bodies, and verify the applicable article references against the current official GDPR text before relying on them.
Revisit measures when the threat landscape, available safeguards, or the nature of your processing changes, and record the rationale for any decision to retain or update controls.