Article 32 is the GDPR's primary data security provision. Rather than mandating specific security controls, it takes a risk-based approach: organizations must assess the risks associated with their processing activities and implement measures proportionate to those risks.
The article explicitly references encryption and pseudonymization as appropriate technical measures, along with the ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems. It also requires a process for regularly testing the effectiveness of security measures.
Article 32 applies to both controllers and processors, and both are liable for security failures. Data breaches often trigger simultaneous regulatory scrutiny under Article 32 (security failure) and Article 28 (inadequate processor oversight), compounding enforcement risk.