GDPR Cybersecurity Compliance: Technical Measures for UK Businesses
UK GDPR Article 32 requires organisations to implement appropriate technical measures to secure personal data. This guide covers the specific controls the ICO expects: encryption, access management, MFA, patch management and tested backups.
Nathan Hill-Haimes
Technical Director
UK GDPR does not hand you a checklist, and that is exactly why it trips businesses up. Article 32 asks for measures "appropriate to the risk" — proportionate, current, and demonstrable. This guide translates that into the specific technical controls the ICO looks for, drawn from its data security guidance and published enforcement decisions, so you can judge whether your own environment would stand up to scrutiny. For the managed version of this work, see our managed cybersecurity services.
What does Article 32 of UK GDPR actually require?
Article 32 requires controllers and processors to implement security "appropriate to the risk", taking account of the state of the art, the costs of implementation, and the nature of the data. It deliberately avoids prescribing technologies. Instead it sets an outcome — personal data must stay confidential, available and intact — and expects you to prove how you achieve it.
That flexibility is practical but creates real uncertainty. The ICO's accountability framework and the NCSC's small-business guidance point to a consistent baseline. The same controls also underpin Cyber Essentials, the UK government scheme AMVIA itself holds at the Plus level — which is why we treat it as the practical floor for GDPR technical compliance.
| Article 32 outcome | Practical control | Where AMVIA delivers it |
|---|---|---|
| Confidentiality | Encryption + access control | Microsoft 365, BitLocker, RBAC |
| Resilience | Tested backup + recovery | Immutable, off-network backups |
| Integrity | Patching + monitoring | Vulnerability management, 24/7 SOC |
| Verification | Logging + audit trail | Microsoft 365 unified audit logs |
Control 1: Does GDPR require encryption?
Article 32 specifically names pseudonymisation and encryption as examples of appropriate measures — the only technologies it cites by name. It is not mandatory in every circumstance, but the loss of an unencrypted device is one of the most reported breach types to the ICO, so the practical answer for most businesses is yes.
Apply encryption in three places:
- At rest: Microsoft 365 encrypts platform data at rest by default. Laptops, phones and USB drives holding personal data need full-disk encryption — BitLocker on Windows, FileVault on macOS.
- In transit: Personal data crossing a network should travel over TLS — HTTPS for web apps, TLS between mail servers, encrypted VPN or remote-desktop sessions.
- Portable media: Unencrypted USB sticks and laptops drive a disproportionate share of reported breaches. Enforce full-disk encryption on every mobile device.
Control 2: How does least-privilege access support compliance?
Limiting access to personal data to those with a genuine business need is a direct expression of Article 5(1)(f) and Article 32. The fewer people and accounts that can reach sensitive data, the smaller your breach surface and the easier your accountability story becomes.
In practice that means:
- Role-based access control: permissions granted by job function, not handed out individually.
- Regular access reviews: confirming permissions stay appropriate when staff change role.
- Offboarding: prompt, complete revocation the day someone leaves.
- Privileged access management: admin accounts used only when needed and monitored closely.
Microsoft Entra ID and Conditional Access give UK SMEs most of this out of the box; our Microsoft 365 security work configures it correctly.
Control 3: Is multi-factor authentication a GDPR requirement?
MFA is not named in Article 32, but the ICO has made clear that the absence of MFA on systems holding personal data is likely to count as a failure to implement appropriate measures — especially in higher-risk contexts. Compromised credentials are the dominant intrusion route, so MFA is now treated as a baseline, not an upgrade.
Stolen or compromised credentials were the initial attack vector in 22% of data breaches in 2024 — surpassing phishing at 16% (Verizon DBIR 2025). Enable MFA on:
- Email accounts — the most common initial access vector
- Cloud platforms: Microsoft 365, Google Workspace, finance and HR systems
- VPN and remote-access connections
- Administrative consoles and management interfaces
The fastest win for most SMEs is enforced MFA across Microsoft 365; see our MFA setup for Microsoft 365 guidance.
Control 4: How quickly must we patch to stay compliant?
Unpatched, internet-facing vulnerabilities are a primary route into data breaches, so the ICO expects a systematic patch-management process with documented timescales. Critical and high-severity patches to internet-facing systems should be applied within 14 days or sooner — the same standard the UK Cyber Essentials scheme enforces.
Devices still running end-of-life operating systems with no security support are a clear compliance risk: there is no patch coming, so the vulnerability is permanent. A continuous vulnerability management process — discover, prioritise, remediate, verify — turns patching from an ad-hoc scramble into evidence you can show the ICO.
Control 5: What backup and recovery does Article 32 demand?
Article 32 explicitly requires "the ability to restore the availability and access to personal data in a timely manner" after an incident. Tested backup and recovery is therefore a legal requirement, not merely business-continuity good practice. An untested backup is an assumption, not a control.
Two rules matter most:
- Off the same network: a backup sitting on the same network as the data it protects offers little defence against ransomware. Use immutable, off-network or offline copies.
- Meet your Recovery Time Objective: define how long the business can run without the data before the disruption itself becomes an Article 32 failure, then size recovery to beat it.
Our Microsoft 365 backup service covers the gap most SMEs miss — Microsoft replicates its platform, but recovering your deleted or ransomware-encrypted content is your responsibility.
Control 6: What logging and monitoring should we keep?
Article 32 requires ongoing testing and evaluation of your controls' effectiveness, which in practice means logging access to systems holding personal data, monitoring for anomalies, and acting on what you find. A log nobody reviews satisfies the letter of the requirement and none of its intent.
Microsoft 365 provides unified audit logging across Exchange, SharePoint, Teams and Entra ID; Microsoft's documentation covers enabling and retaining it. Retain logs for at least 90 days, and longer for higher-risk profiles. Most SMEs lack the capacity to watch logs around the clock, which is where 24/7 security monitoring backed by a human SOC turns raw logs into detection.
How do we document technical controls for accountability?
The accountability principle requires you not only to implement controls but to evidence them. If you cannot demonstrate a control was working, the ICO may treat it as if it were not there. Documentation is what converts good security into defensible compliance.
Maintain three things:
- A record of measures in place, mapped to your Article 32 risk assessment.
- Evidence they work: patch-compliance reports, access-review outcomes, backup-test results.
- A review process at sensible intervals, with dates and owners.
AMVIA implements and documents UK GDPR technical controls for UK businesses, producing the evidence trail that supports accountability and, in an ICO inquiry, shows appropriate measures were genuinely in place. One provider, security-first, Microsoft-certified.
Can You Demonstrate Your GDPR Technical Controls?
The ICO expects organisations to show that appropriate technical measures are in place — not just assert it. AMVIA can implement and document the controls needed to satisfy this obligation.
Frequently Asked Questions
Article 32 cites encryption and pseudonymisation as examples of appropriate technical measures. It does not mandate encryption in every case, but the ICO expects devices holding personal data — particularly portable devices and removable media — to be encrypted. The loss of an unencrypted device is consistently one of the most reported breach types to the ICO.
Risk is judged by the nature of the data, the volume processed, the likelihood of harm, and the impact on individuals. Special category data — health, ethnicity, religion, biometrics — carries higher risk. Processing large volumes of sensitive personal data demands stronger controls than handling limited business contact details, so your measures should scale with the risk you actually hold.
Microsoft and Google act as data processors and are responsible for securing the underlying platform, with contractual terms that satisfy Article 28. But you remain the controller. Configuring their services correctly is your duty — a Microsoft 365 tenant without MFA is your responsibility, not Microsoft's. Compliance is shared, never outsourced entirely.
Retain at minimum the access, authentication, administrator-activity and data-export logs for systems holding significant personal data. Microsoft 365 unified audit logging covers Exchange, SharePoint, Teams and Entra ID. Keep logs for at least 90 days; 12 months is more appropriate for most compliance purposes and for investigating incidents that surface slowly.
The accountability principle requires records that demonstrate compliance: what controls are in place and why they suit the risk (your Article 32 risk assessment), evidence they function correctly (patch reports, access reviews, backup tests), and a process for reviewing their adequacy at appropriate intervals. Documentation is what you show the ICO if asked.
Related Reading
GDPR Compliance: A Comprehensive Implementation Guide
The full GDPR implementation process, from data mapping through to breach notification readiness.
ISO 27001 Cybersecurity: UK Implementation Guide
How ISO 27001 provides the governance framework that supports and evidences GDPR technical compliance.
Password Protection & Authentication
How strong authentication — including MFA — meets GDPR access control requirements.
Protect your business → Get Cybersecurity Assessment