Answers to the questions practitioners most commonly ask about SotA.
Does 'state of the art' mean an organisation must always deploy the newest or most advanced security technology available?
No. This is a common misconception. The GDPR references the 'state of the art' in provisions on security of processing and data protection by design and by default, but it does not require adopting the single newest or most expensive technology. The obligation is generally understood as a proportionate standard: controllers and processors must take account of the state of the art alongside the costs of implementation, the nature, scope, context and purposes of processing, and the risks to individuals. The result is a risk-based and context-dependent assessment rather than a fixed technological requirement, and the appropriate baseline can shift over time as accepted practices evolve.
Is 'state of the art' a fixed technical standard that regulators have defined precisely?
Not in the sense of a single codified specification. The concept is expressed at a general level in the Regulation and is not exhaustively defined by a fixed list of approved technologies. Its content is informed by evolving industry practice, guidance from regulators and standards bodies, and the risk assessment for the specific processing. Because interpretation can develop and may vary between contexts and supervisory authorities, the appropriate measures should be reassessed periodically rather than treated as settled once and for all. Readers should verify current guidance against official sources.
How can an organisation practically assess what the 'state of the art' is for a given processing activity?
In most cases the assessment starts by identifying the processing operations and the associated risks to individuals, then reviewing what protective measures are generally accepted and reasonably available for comparable activities. Organisations typically look to recognised standards, published regulatory guidance, sector practice, and outputs from standards bodies, and then weigh these against the cost of implementation and the level of risk. The aim is a documented, proportionate judgement rather than a claim to use the most advanced option. The specifics will depend on context, so the reasoning behind chosen measures should be recorded.
How often should 'state of the art' considerations be revisited?
Because accepted practices and available safeguards evolve, the assessment is generally treated as ongoing rather than one-off. Many organisations review it periodically and also when there is a material change, such as a new processing activity, a change in the risk profile, an emerging vulnerability, or updated regulatory guidance. The appropriate cadence is a matter of judgement based on the risk involved and is not fixed by a specific interval in the Regulation text.
How does 'state of the art' interact with the cost of implementation when choosing measures?
The Regulation frames the state of the art as one factor to be balanced against the costs of implementation and against the nature, scope, context, purposes and risks of the processing. This means an available advanced measure need not be adopted if it is disproportionate to the risk, and conversely low cost is not a justification for inadequate protection where risk is high. In practice the balance is struck through a documented risk assessment, and the outcome is context and risk dependent rather than dictated purely by what is technically possible.
How should an organisation document its 'state of the art' decisions to support accountability?
Given the GDPR's general emphasis on accountability, it is typically advisable to record the reasoning behind the measures selected: the risks considered, the options assessed, the standards or guidance relied upon, the cost and proportionality analysis, and any decision to accept or mitigate residual risk. Where the processing is likely to result in high risk, this reasoning may form part of a Data Protection Impact Assessment under Article 35, though state of the art considerations also arise more broadly. Maintaining such records helps demonstrate that measures were appropriate at the time and supports periodic reassessment as practices evolve.