Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: SV

Artikel 32 Säkerhet i samband med behandlingen


Summary What does Article 32 of the GDPR regulation say?

This article sets out the security obligations for both controllers and processors when handling personal data.

Rather than prescribing fixed technical standards, it takes a risk-based approach, requiring that security measures be calibrated to the nature and context of the processing and the potential harm to individuals.

The article provides examples of appropriate measures, covering encryption, system resilience, incident recovery, and regular testing, while also extending the obligation to anyone acting under the authority of the controller or processor.

Important points:

  • Controllers and processors must implement technical and organisational security measures appropriate to the risk posed by their processing activities.
  • Adherence to an approved code of conduct (Article 40) or certification mechanism (Article 42) can be used as evidence of compliance with these security requirements.
  • Ensure that any person with access to personal data under your authority only processes it on the controller's instructions, unless required otherwise by law.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Med beaktande av den senaste utvecklingen, genomförandekostnaderna och behandlingens art, omfattning, sammanhang och ändamål samt riskerna, av varierande sannolikhetsgrad och allvar, för fysiska personers rättigheter och friheter ska den personuppgiftsansvarige och personuppgiftsbiträdet vidta lämpliga tekniska och organisatoriska åtgärder för att säkerställa en säkerhetsnivå som är lämplig i förhållande till risken, inbegripet, när det är lämpligt

      1. pseudonymisering och kryptering av personuppgifter,

      2. förmågan att fortlöpande säkerställa konfidentialitet, integritet, tillgänglighet och motståndskraft hos behandlingssystemen och -tjänsterna,

      3. förmågan att återställa tillgängligheten och tillgången till personuppgifter i rimlig tid vid en fysisk eller teknisk incident,

      4. ett förfarande för att regelbundet testa, undersöka och utvärdera effektiviteten hos de tekniska och organisatoriska åtgärder som ska säkerställa behandlingens säkerhet.

    1. Vid bedömningen av lämplig säkerhetsnivå ska särskild hänsyn tas till de risker som behandling medför, i synnerhet från oavsiktlig eller olaglig förstöring, förlust eller ändring eller till obehörigt röjande av eller obehörig åtkomst till de personuppgifter som överförts, lagrats eller på annat sätt behandlats.

    1. Anslutning till en godkänd uppförandekod som avses i artikel 40 eller en godkänd certifieringsmekanism som avses i artikel 42 får användas för att visa att kraven i punkt 1 i den här artikeln följs.

    1. Den personuppgiftsansvarige och personuppgiftsbiträdet ska vidta åtgärder för att säkerställa att varje fysisk person som utför arbete under den personuppgiftsansvariges eller personuppgiftsbiträdets överinseende, och som får tillgång till personuppgifter, endast behandlar dessa på instruktion från den personuppgiftsansvarige, om inte unionsrätten eller medlemsstaternas nationella rätt ålägger honom eller henne att göra det.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod