Skip to main content
Category: Privacy Governance & Design

State of the Art Consideration

Also known as: SotA, State of the Art, State-of-the-Art Analysis
Simply put

State of the art refers to the current level of technical and organisational development achieved in a given field, science, or technology. In a data protection context it is generally used as a reference point for what is realistically achievable when deciding how to protect personal data. Because it reflects an evolving level of development rather than a fixed standard, what qualifies as state of the art changes over time and can differ between fields.

Formal definition

State of the art denotes the level of development achieved at a particular time in a market, application domain, science, or technology, and functions as a benchmark for assessing the adequacy of measures. Under the GDPR the concept appears as a factor to be weighed alongside costs of implementation, the nature, scope, context and purposes of processing, and the risks to individuals, notably when determining appropriate technical and organisational measures. It is a relative and dynamic criterion rather than a defined technical standard, so the assessment must be made contextually and revisited as technology evolves; the evidence provided here describes the general meaning of the term but does not establish the precise GDPR article references or thresholds, which should be verified against the current official text and applicable regulatory guidance.

Why it matters

State of the art functions as a moving benchmark in data protection, not a fixed technical specification. When the GDPR calls for a state-of-the-art consideration in selecting technical and organisational measures, it generally means that the adequacy of a safeguard must be judged against the current level of development achieved in the relevant field or technology, rather than against a static list of controls. This matters because a measure that was considered reasonable at one point may later be regarded as insufficient once the field advances, so a controller or processor cannot treat a one-time assessment as permanently valid.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads typically rely on the state-of-the-art consideration when reviewing whether technical and organisational measures remain appropriate. Because the benchmark is dynamic, they should build periodic re-assessment into their governance processes rather than treating an initial evaluation as settled, and should record the reasoning applied at each review.
Engineers and Security Architects
Those designing systems that process personal data generally need to interpret state of the art in relation to the specific application domain and available technology. Since expectations differ between fields, engineers may need to justify why a chosen safeguard reflects the current level of development, and to revisit those choices as the underlying technology advances.
Privacy Counsel and Legal Advisers
Lawyers advising on GDPR compliance should treat state of the art as a relative and evolving criterion weighed against implementation costs and processing risks, rather than as a defined standard. The precise article references and any thresholds should be verified against the current official text and applicable regulatory guidance, and advice should acknowledge that interpretations may vary between fields and over time.

Inside SotA

Statutory anchor
The concept of the 'state of the art' appears in the GDPR's security and data-protection-by-design provisions, where controllers and processors are required to take account of the state of the art alongside implementation costs, and the nature, scope, context and purposes of processing, when determining appropriate technical and organisational measures. It functions as a benchmark for the reasonableness of safeguards rather than a fixed technical standard.
Dynamic, evolving benchmark
The state of the art is not a static list of technologies. It reflects the current level of technical development that is available and reasonably deployable at a given time, meaning the expected baseline of protection generally rises as technologies mature and become more widely adopted.
Balancing element within a risk assessment
State of the art is one factor weighed together with cost of implementation and the risks to individuals. It does not require adopting the most advanced technology available irrespective of cost or proportionality; measures are assessed for appropriateness in light of the specific risks presented by the processing.
Application to security and to design/default
The consideration is relevant both to the security of processing and to data protection by design and by default, informing choices such as encryption, pseudonymisation, access controls, and architectural decisions made at the outset of and throughout processing activities.
Distinction from 'best available technology'
State of the art typically sits between minimum acceptable practice and the theoretical cutting edge. It generally refers to established, proven and available methods rather than experimental or the single most sophisticated solution, subject to assessment in each case.

Common questions

Answers to the questions practitioners most commonly ask about SotA.

Does 'state of the art' mean an organisation must always deploy the newest or most advanced security technology available?
No. This is a common misconception. The GDPR references the 'state of the art' in provisions on security of processing and data protection by design and by default, but it does not require adopting the single newest or most expensive technology. The obligation is generally understood as a proportionate standard: controllers and processors must take account of the state of the art alongside the costs of implementation, the nature, scope, context and purposes of processing, and the risks to individuals. The result is a risk-based and context-dependent assessment rather than a fixed technological requirement, and the appropriate baseline can shift over time as accepted practices evolve.
Is 'state of the art' a fixed technical standard that regulators have defined precisely?
Not in the sense of a single codified specification. The concept is expressed at a general level in the Regulation and is not exhaustively defined by a fixed list of approved technologies. Its content is informed by evolving industry practice, guidance from regulators and standards bodies, and the risk assessment for the specific processing. Because interpretation can develop and may vary between contexts and supervisory authorities, the appropriate measures should be reassessed periodically rather than treated as settled once and for all. Readers should verify current guidance against official sources.
How can an organisation practically assess what the 'state of the art' is for a given processing activity?
In most cases the assessment starts by identifying the processing operations and the associated risks to individuals, then reviewing what protective measures are generally accepted and reasonably available for comparable activities. Organisations typically look to recognised standards, published regulatory guidance, sector practice, and outputs from standards bodies, and then weigh these against the cost of implementation and the level of risk. The aim is a documented, proportionate judgement rather than a claim to use the most advanced option. The specifics will depend on context, so the reasoning behind chosen measures should be recorded.
How often should 'state of the art' considerations be revisited?
Because accepted practices and available safeguards evolve, the assessment is generally treated as ongoing rather than one-off. Many organisations review it periodically and also when there is a material change, such as a new processing activity, a change in the risk profile, an emerging vulnerability, or updated regulatory guidance. The appropriate cadence is a matter of judgement based on the risk involved and is not fixed by a specific interval in the Regulation text.
How does 'state of the art' interact with the cost of implementation when choosing measures?
The Regulation frames the state of the art as one factor to be balanced against the costs of implementation and against the nature, scope, context, purposes and risks of the processing. This means an available advanced measure need not be adopted if it is disproportionate to the risk, and conversely low cost is not a justification for inadequate protection where risk is high. In practice the balance is struck through a documented risk assessment, and the outcome is context and risk dependent rather than dictated purely by what is technically possible.
How should an organisation document its 'state of the art' decisions to support accountability?
Given the GDPR's general emphasis on accountability, it is typically advisable to record the reasoning behind the measures selected: the risks considered, the options assessed, the standards or guidance relied upon, the cost and proportionality analysis, and any decision to accept or mitigate residual risk. Where the processing is likely to result in high risk, this reasoning may form part of a Data Protection Impact Assessment under Article 35, though state of the art considerations also arise more broadly. Maintaining such records helps demonstrate that measures were appropriate at the time and supports periodic reassessment as practices evolve.

Common misconceptions

State of the art requires deploying the newest or most expensive technology available.
The requirement is qualified by cost of implementation and proportionality to risk. Controllers and processors must consider available technical developments but are generally expected to select appropriate, not maximal, measures based on the risks to individuals in the specific context.
Once appropriate measures are selected, the state-of-the-art obligation is satisfied permanently.
Because it is a dynamic benchmark that tracks technical progress, measures that were appropriate at one time may become inadequate as technology advances. Ongoing review is generally expected rather than a one-off assessment.
State of the art is a precise, universally agreed technical standard.
It is an open-ended legal benchmark rather than a defined checklist. Interpretation can vary, and supervisory authority guidance and sector practice inform what is considered appropriate; practitioners should verify current expectations against official texts and guidance.

Best practices

Document how the state of the art was considered alongside implementation cost and the specific risks to individuals, so that the reasoning behind chosen technical and organisational measures is demonstrable.
Treat the assessment as recurring: schedule periodic reviews of security and design measures to account for evolving technical developments and changing risk profiles.
Assess measures proportionately to the risk of the processing rather than defaulting to either minimum practice or the most advanced available technology.
Integrate the state-of-the-art analysis into data-protection-by-design decisions at the outset of new processing activities, not only when addressing security after deployment.
Consult current supervisory authority guidance and recognised sector practice to inform what is considered appropriate, and note where interpretation is uncertain or evolving.
Retain evidence of the alternatives considered and the rationale for selection, including cost and proportionality factors, to support accountability.