State of the Art
State of the art refers to the highest level of general development in a device, technique, or field of science reached at a particular point in time. In a data protection context, it is a benchmark used to judge how advanced the security and privacy measures an organisation adopts should be, taking into account what is currently achievable. Because it reflects development at a given moment, what counts as state of the art evolves over time.
State of the art denotes the level of development of a device, procedure, process, technique, or science achieved at a particular time, representing the leading edge of what is generally available and technically feasible rather than purely experimental. As a general concept, it functions as a moving, time-dependent benchmark that must be reassessed as technology advances. Note: the evidence packet provided contains only general-language and unrelated sources; it does not include the GDPR text or official guidance, so the specific role of 'state of the art' as a factor in GDPR obligations (for example in relation to security of processing or data protection by design) is not established by this evidence and should be verified against the current official Regulation text and competent supervisory authority guidance before being relied upon in a compliance program.
Why it matters
In data protection, the phrase "state of the art" is significant because it establishes a moving benchmark rather than a fixed standard. An organisation cannot demonstrate that its safeguards are adequate simply by pointing to measures that were considered advanced in the past; the concept requires that measures be assessed against the highest level of general development reached at the relevant point in time. Because this level evolves as technology and techniques advance, a control that was defensible when implemented may need to be reassessed as newer, generally available approaches emerge.
The evidence available here draws only from general-language sources, which define "state of the art" as the highest level of development of a device, procedure, process, technique, or science achieved at a particular time. It does not include the GDPR text or supervisory authority guidance. As a result, the specific weight this concept carries within particular data protection obligations is not established by this evidence and should be confirmed against the current official Regulation text and competent regulator guidance before it is relied upon in a compliance program.
Because the benchmark is time-dependent, treating it as a one-off assessment risks leaving safeguards behind the leading edge of what is generally available. Organisations should generally treat the evaluation as recurring, revisiting whether adopted measures still reflect the current level of development rather than an earlier snapshot.
Who it's relevant to
Inside State of the Art
Common questions
Answers to the questions practitioners most commonly ask about State of the Art.