Industry
SECURITYFRAMEWORKGDPR

Pentesting for GDPR

GDPR is the EU regulation protecting personal data. It applies to controllers and processors anywhere that handle data of people in the EU. Article 32 requires technical and organizational measures and regular evaluation that they stay effective, which penetration testing directly supports. Fines can reach €20 million or 4% of global annual turnover, whichever is higher.

The controls we cover

Requirement summary

Controllers and processors must, as appropriate, operate a process for regularly testing, assessing, and evaluating the effectiveness of the technical and organisational measures used to secure processing.

AISafe records test scope, findings, impact, and retest status, giving Article 32(1)(d) technical evidence that security measures stay effective over time.

Requirement summary

Controllers and processors must be able to ensure the ongoing confidentiality, integrity, availability, and resilience of their processing systems and services.

AISafe exercises authentication, authorization, and data-exposure paths to surface weaknesses that threaten the confidentiality, integrity, and availability of processed personal data.

Requirement summary

Controllers must implement measures to apply data-protection principles effectively and integrate safeguards into processing, so that by default only the personal data necessary for each purpose is processed.

During source-code review, AISafe checks whether data collection, storage, and exposure match the stated purpose and whether safeguards are actually wired in by default.

Quick facts

ApplicabilityControllers and processors anywhere that handle personal data of people in the EU.
RequirementYes. Regular testing, assessment, and evaluation of security measures is a legal duty under Article 32.
CostRisk-based; a small controller with low-risk processing carries a lighter duty and cost than a large processor of sensitive data.
CadenceNot fixed; regular evaluation, commonly yearly, with retests after significant changes.

Related frameworks

Get your Audit Evidence right now

Run a security assessment of your system, or contact us if your compliance programme requires additional support.