Pentesting for GDPR
GDPR is the EU regulation protecting personal data. It applies to controllers and processors anywhere that handle data of people in the EU. Article 32 requires technical and organizational measures and regular evaluation that they stay effective, which penetration testing directly supports. Fines can reach €20 million or 4% of global annual turnover, whichever is higher.
The controls we cover
Requirement summaryControllers and processors must, as appropriate, operate a process for regularly testing, assessing, and evaluating the effectiveness of the technical and organisational measures used to secure processing.
AISafe records test scope, findings, impact, and retest status, giving Article 32(1)(d) technical evidence that security measures stay effective over time.
Requirement summaryControllers and processors must be able to ensure the ongoing confidentiality, integrity, availability, and resilience of their processing systems and services.
AISafe exercises authentication, authorization, and data-exposure paths to surface weaknesses that threaten the confidentiality, integrity, and availability of processed personal data.
Requirement summaryControllers must implement measures to apply data-protection principles effectively and integrate safeguards into processing, so that by default only the personal data necessary for each purpose is processed.
During source-code review, AISafe checks whether data collection, storage, and exposure match the stated purpose and whether safeguards are actually wired in by default.
Quick facts
| Applicability | Controllers and processors anywhere that handle personal data of people in the EU. |
| Requirement | Yes. Regular testing, assessment, and evaluation of security measures is a legal duty under Article 32. |
| Cost | Risk-based; a small controller with low-risk processing carries a lighter duty and cost than a large processor of sensitive data. |
| Cadence | Not fixed; regular evaluation, commonly yearly, with retests after significant changes. |
