Service
GDPR penetration testing: evidence for Article 32
GDPR penetration testing helps show that security measures are tested regularly, as Article 32 expects. So the test protects personal data and produces evidence at the same time.
- Fixed fee before we start
- Named tester in writing
- Retest and attestation letter
What GDPR says about testing
Article 32 asks controllers and processors to have a process for regularly testing and evaluating security measures. However, it does not name penetration testing specifically.
Therefore a pentest is one strong way to meet the duty. Also, it shows regulators and customers that testing actually happened.
What GDPR penetration testing focuses on
Scope follows personal data. For example, systems that store customer records or process sensitive categories.
- Applications holding personal data
- APIs that expose customer records
- Access controls between customers
- Storage and backups
- Administrative access paths
GDPR penetration testing readiness check
Tick what is in place.
Your result appears here as you tick, so you can see what is still open.
Protecting data during GDPR penetration testing
The test itself must respect data protection. So rules of engagement limit how testers handle any personal data they reach.
| Safeguard | Purpose |
|---|---|
| Written authorisation | Lawful basis for the activity |
| Data processing terms | The tester acts on your instructions |
| Minimal data access | Prove access without bulk copying |
| Secure deletion | Nothing kept after the engagement |
Turning results into evidence
Keep the report, remediation records and retest letter together. As a result, you can show a cycle of testing and improvement, which is what Article 32 describes.
In addition, link findings to your risk register. The regulation text is on GDPR text on EUR-Lex.
Fees and timing
Packages start at $5,900 for one asset and $14,500 for up to three, each as a fixed fee. One retest inside 30 days is included, and the report is delivered in 10 working days. Testing is delivered by vetted third-party practitioners under our project management.
Also involve your data protection lead early. Because they own the record of processing, they can confirm which systems matter most. So the scope follows real risk. In addition, record the test in your security documentation, because it supports accountability under the regulation.
GDPR penetration testing questions
Is GDPR penetration testing mandatory?
GDPR requires regular testing of security measures. A pentest is a common way to meet it.
Will testers see personal data during GDPR penetration testing?
Possibly, so rules limit access and handling, and nothing is kept afterwards.
How often should GDPR penetration testing happen?
Regularly, commonly yearly and after major changes.
Is a retest included?
Yes. One retest inside 30 days is included.
Related guides
Scope your GDPR penetration testing
Tell us which systems hold personal data. We reply with a fixed fee, usually within four working hours.
Get my fixed-fee quote