Skip to content
Thornbury Labs
Authorised testing only. We test with your written authorisation, so scope and rules are agreed before testing begins. Testing is delivered by vetted third-party practitioners, and we do not describe our work as certified.

Service

GDPR penetration testing: evidence for Article 32

GDPR penetration testing helps show that security measures are tested regularly, as Article 32 expects. So the test protects personal data and produces evidence at the same time.

  • Fixed fee before we start
  • Named tester in writing
  • Retest and attestation letter
Gdpr penetration testing: agree the scope, test with care and keep the evidence

What GDPR says about testing

Article 32 asks controllers and processors to have a process for regularly testing and evaluating security measures. However, it does not name penetration testing specifically.

Therefore a pentest is one strong way to meet the duty. Also, it shows regulators and customers that testing actually happened.

What GDPR penetration testing focuses on

Scope follows personal data. For example, systems that store customer records or process sensitive categories.

  • Applications holding personal data
  • APIs that expose customer records
  • Access controls between customers
  • Storage and backups
  • Administrative access paths

GDPR penetration testing readiness check

Tick what is in place.

Your result appears here as you tick, so you can see what is still open.

Protecting data during GDPR penetration testing

The test itself must respect data protection. So rules of engagement limit how testers handle any personal data they reach.

SafeguardPurpose
Written authorisationLawful basis for the activity
Data processing termsThe tester acts on your instructions
Minimal data accessProve access without bulk copying
Secure deletionNothing kept after the engagement

Turning results into evidence

Keep the report, remediation records and retest letter together. As a result, you can show a cycle of testing and improvement, which is what Article 32 describes.

In addition, link findings to your risk register. The regulation text is on GDPR text on EUR-Lex.

Fees and timing

Packages start at $5,900 for one asset and $14,500 for up to three, each as a fixed fee. One retest inside 30 days is included, and the report is delivered in 10 working days. Testing is delivered by vetted third-party practitioners under our project management.

Also involve your data protection lead early. Because they own the record of processing, they can confirm which systems matter most. So the scope follows real risk. In addition, record the test in your security documentation, because it supports accountability under the regulation.

GDPR penetration testing questions

Is GDPR penetration testing mandatory?

GDPR requires regular testing of security measures. A pentest is a common way to meet it.

Will testers see personal data during GDPR penetration testing?

Possibly, so rules limit access and handling, and nothing is kept afterwards.

How often should GDPR penetration testing happen?

Regularly, commonly yearly and after major changes.

Is a retest included?

Yes. One retest inside 30 days is included.

Related guides

Scope your GDPR penetration testing

Tell us which systems hold personal data. We reply with a fixed fee, usually within four working hours.

Get my fixed-fee quote