Does GDPR Require Penetration Testing? What Article 32 Actually Says
Quick Answer
GDPR does not literally require "penetration testing" — those words never appear in the Regulation. Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of security measures, and the UK ICO explicitly names penetration testing and vulnerability scanning as practical ways to do that. No frequency is set in the text — it is risk-proportionate. Article 32 binds processors as well as controllers, so a SaaS company processing customer data has its own obligation, independent of its customers.
The Four Measures in Article 32(1)
Article 32(1) requires controllers and processors to implement technical and organisational measures appropriate to the risk, and lists four examples — the list is illustrative, not exhaustive (the text says "including inter alia as appropriate").
| § | Measure |
|---|---|
| (a) | Pseudonymisation and encryption of personal data |
| (b) | Ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services |
| (c) | Ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident |
| (d) | A process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing |
Source: Regulation (EU) 2016/679, Article 32(1) — EUR-Lex · gdpr-info.eu
What Regulators Say About Testing
The UK Information Commissioner's Office (ICO), in its guidance on security, confirms that Article 32 requires a process of regularly testing the effectiveness of security measures, that the appropriate extent of testing depends on what and how the organisation processes personal data, and that this is commonly done through vulnerability scanning and penetration testing among other methods. The European Data Protection Board's (EDPB) guidance on Article 32 similarly frames testing as risk-based rather than prescribing a fixed method or schedule. Neither source sets a mandatory frequency — the obligation is to have a genuine, regularly-exercised process, sized to your actual risk.
How Often? There Is No Number in the Regulation
This is where most competing pages get it wrong, and it is worth being precise about. Article 32(1) sets a standard — measures "appropriate to the risk," taking into account "the state of the art, the costs of implementation and the nature, scope, context and purposes of processing" — not a cadence. Nowhere does the text say "annually," "every 12 months," or any other fixed interval.
In practice, what determines frequency is your own risk assessment: how sensitive the data is, how much your system changes, whether you've had an incident, and what your customers' contracts or your cyber insurance renewal specifically ask for. Annual testing is a common industry convention, not a GDPR requirement — treat it as a reasonable default, not a legal citation.
If You Are a Processor, This Is Your Obligation Too
Article 32(1) opens with "the controller and the processor shall implement..." — it names both roles explicitly. A SaaS company processing its customers' end-user data is a processor, and its Article 32(1)(d) testing obligation exists independently of whatever its own customers do on their side.
In practice, this usually surfaces first as a contractual requirement: your customer's Data Processing Agreement asks you to demonstrate that you test your own security measures, sometimes with a specific evidence format. This is the same document category covered by our vendor security questionnaire page — the questionnaire is usually where the Article 32(1)(d) obligation becomes concrete and time-bound.
Testing by a Supplier Outside the EEA
We are based in Moldova, which is not on the European Commission's list of countries with an adequacy decision. In practice this means every engagement with an EU-based client is set up through a Data Processing Agreement and Standard Contractual Clauses (SCCs) before any testing begins — not as an exception, but as our standard onboarding step for cross-border work.
For your own evidence file, this is what typically gets kept alongside the test report: the signed DPA, the executed SCCs, and confirmation of the specific data categories (if any) the testing provider could access during the engagement. If your legal or security team wants to review these before contracting, we provide them in advance of any scoping call.
What Evidence Looks Like
A Web App Vulnerability Assessment produces a scored report and a signed Attestation Letter in 5 business days.
Start with Vulnerability Assessment — €539Penalties
Article 32 infringements are assessed under the lower of the two GDPR fining scales — do not confuse it with the higher scale that applies to different obligations.
| Scale | Applies to | Maximum fine |
|---|---|---|
| Article 83(4) infringements | Obligations of controllers and processors, including Article 32 security measures | Up to €10,000,000 or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher |
| Article 83(5) infringements | Basic principles of processing, data subject rights, international transfers (a different, higher scale — not the one Article 32 falls under) | Up to €20,000,000 or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher |
This page explains our understanding of Article 32 and is not legal advice. We are a security testing provider, not a law firm — for a binding interpretation of your specific obligations, consult your Data Protection Officer or legal counsel.
Frequently Asked Questions
Does GDPR require penetration testing?+
How often does GDPR require testing?+
Is a vulnerability scan enough?+
We are a processor, not a controller — does this apply to us?+
Our supplier is outside the EU — is that a problem?+
What documentation should we keep?+
What are the fines?+
Does an ISO 27001 certificate cover Article 32?+
Is a €539 vulnerability assessment enough for GDPR?+
Document Your Article 32(1)(d) Process
Fixed prices, published on every tier's own page. No sales call required to see a number.
