Three months on from the GDPR effective date, the honest assessment of GDPR cybersecurity compliance is that 25 May changed almost nothing about what security teams should be doing, and almost everything about what they have to be able to prove. The controls were good practice before. What is new is that failure is now a regulatory event with a defined audience, a statutory timetable and a documented standard of care that somebody else will assess after the fact. That distinction is not semantic. It determines where the money goes, and in the first quarter of enforcement it has mostly gone to the wrong place.
Article 32 does not contain a control list, and that is deliberate
The security obligation sits in a single article, and it refuses to be a checklist. Controllers and processors must implement technical and organisational measures appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing. Four examples are named: pseudonymisation and encryption; the ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems; the ability to restore availability and access to personal data in a timely manner after a physical or technical incident; and a process for regularly testing, assessing and evaluating the effectiveness of those measures. The first two are familiar. The third and fourth are where most organisations are exposed, and neither got attention during the run-up because neither produces a document a lawyer can file. Restoration is the quieter of the two. Nearly every organisation can prove it takes backups. Very few can prove it restores them, on a known timetable, into a working system, with the data intact. Backup success reports measure that a job completed, not that a business process can resume. An availability obligation that is written as "restore in a timely manner" is an obligation to have tested the restore, and the number of finance and HR systems in this region whose full recovery has been rehearsed in the last two years is small. The fourth is the sleeper. Regular testing and evaluation of effectiveness is not framed as a maturity goal. It is framed as part of the measure itself. A control that has never been tested is, on the plain text, not a compliant control, however well it is documented.
The gap the first three months exposed
Most GDPR programmes were run by legal and produced artefacts: records of processing, privacy notices, updated contracts, a consent review, a data protection impact assessment template. Security was consulted, usually late, and usually to confirm that a control existed. The result is a predictable set of findings that are now surfacing in customer audits rather than in regulatory ones. Inventories describe systems rather than data flows. An asset register that lists a hundred and forty servers is not the same as knowing which of them hold personal data, which categories, whose, and where copies land. The first question in any incident is scope, and scope is answered from data flows. Logging is sized for operations rather than for investigation. Retention of thirty days, no centralised collection, no logging at all on the file shares and mailboxes where the sensitive material actually sits. An organisation that cannot establish what was accessed will, when something happens, have to assume the worst version of it. That assumption is expensive in both directions: over-notification damages relationships, and under-notification is the thing regulators have been clearest about. Encryption is claimed rather than owned. "The platform encrypts at rest" is true and largely irrelevant to the threat model, since the common failure is over-permissive access by a legitimate account, not somebody walking out with a disk. Encryption in the sense Article 32 cares about is the kind that limits who can read data, which means key custody, and key custody is a question about people. Access review exists as a policy and not as an event. Joiners are provisioned quickly because someone is waiting. Leavers are deprovisioned eventually. The accumulated middle, where people changed roles and kept both sets of permissions, is the single most common finding in every security assessment that has ever been run, and it is now a documented failure of an appropriate organisational measure.
What actually changed in the risk calculation
Two things, and they are worth stating precisely because most of the commentary this summer has been about fine ceilings. First, the standard of care became external. Before May, whether a control was adequate was a matter of internal judgement, an auditor's opinion, or a customer's questionnaire. It is now a question that a supervisory authority can reach a conclusion on, retrospectively, after an incident, with the benefit of hindsight and the incident report in front of it. Second, the measures in place became an explicit factor in what happens next. The regulation lists the technical and organisational measures implemented as something to be taken into account when deciding on a corrective action and its amount. Read plainly, that means the security programme's own documentation is evidence in a proceeding that has not happened yet. Organisations that treat their control documentation as a marketing exercise are drafting exhibits.
Practical Guidance for a GDPR Security Compliance Audit
- Start from data flows, not from the asset register. Identify the systems holding personal data, the categories held, the copies downstream, and who can read each one. Everything else is unanchored.
- Test a restore and write down the result. Pick the two systems with the most personal data, restore them into an isolated environment, record the elapsed time and what was missing. This is the single cheapest piece of Article 32 evidence available.
- Fix logging where the sensitive data is, not where the servers are. Mailboxes, file shares, HR systems, database exports. Establish how long you retain logs and whether they would answer the scope question.
- Treat non-production copies as production. Full-fidelity refreshes into test environments remain the most common serious finding, and the fix is a masking routine rather than a policy.
- Turn the access review into a dated event with a named owner. Quarterly, evidenced, with removals actually executed. A policy that describes a review nobody performs is worse than no policy, because it documents the intent you failed to meet.
- Ask your hosting and support providers what they can see. Standing administrative access held by an integrator is a technical and organisational measure question whether or not anybody has classed it as one.
- Record decisions you did not take, with dates and reasons. "State of the art" and "cost of implementation" are defences only if you can show you weighed them at the time.
- Rehearse the first four hours. Who declares, who investigates, who assesses scope, who drafts the notification, who contacts the customer whose contract requires telling them within twenty-four. The discovery that these are four different unavailable people is best made in a rehearsal.
The Regional Angle
For most organisations here the obligation did not arrive from a regulator. There is no general federal data protection statute in the UAE or Saudi Arabia, and what applies instead is a patchwork: the DIFC and ADGM regimes for entities inside them, Qatar's law, central bank and health sector rules, and, since May, European obligations transmitted through customer contracts and European parent companies. The practical form GDPR takes in this market is a security schedule with an audit right attached, and the new experience of this summer is that the audit right is being exercised. That changes the audience for the evidence. A European customer's security team asking for penetration test results, access review records and a restoration test is more demanding in the short run than any supervisory authority, because it arrives with a renewal date. Several organisations discovered in June and July that their Article 32 position was going to be assessed by a procurement function in Frankfurt long before it was ever assessed in Abu Dhabi. The estate structure complicates the answer. A large share of regional systems are administered by integrators, with backups, monitoring, patching and privileged credentials sitting outside the organisation that carries the obligation. Three questions follow and most contracts answer none of them: who holds the keys, who can restore, and who tells you when something happens. Where the same integrator administers the system, holds the encryption keys and operates the backup, the technical measures are real and the organisational ones are a single point of trust. Timing is its own regional problem. Change windows this year were already contested by the VAT-driven finance system work that consumed the first half, and the weekend structure, Ramadan and the Eid periods compress the available maintenance calendar further. Restoration tests and control remediation compete for the same narrow windows as everything else, which is the real reason they slip rather than any dispute about their value. Groups spanning mainland, free zone and DIFC or ADGM entities have the additional problem that the applicable baseline differs by entity while the infrastructure is shared, so the honest scoping question is which entity is exposed, not whether the group is compliant.
The objection worth taking seriously
The objection is that nothing changed on 25 May. Every control discussed here was already required by payment card standards, by ISO 27001 certification, by customer contracts, by insurers, and by ordinary professional judgement. What the regulation added was a consultancy market, a poster in the lobby, and a large volume of documentation whose primary function is to demonstrate that documentation exists. The harder version is more uncomfortable. The claim that GDPR would raise the security baseline is not testable in three months, and the observable effect so far is budget moving from controls to legal advice, gap assessments and records of processing. That is not a neutral reallocation. Money spent producing an inventory that will be accurate for one day is money not spent on logging that would have answered the scope question. There is a real chance the first two years of this regime make organisations better documented and no harder to breach. The counter is narrow but holds. Two things are genuinely new: an evidence standard that converts "we believe we are secure" into "show me the test result", and an external consequence severe enough to end an argument that security teams have been losing internally for a decade. Neither improves anything on its own. Both make deferral expensive, which is the mechanism by which anything ever gets funded. The defensible position for the next twelve months is to spend on measures that reduce exposure and that you can evidence, in that order, and to let the documentation fall out of the work rather than be the work.
Common Questions
Does GDPR require encryption?
No. It names encryption as an example of an appropriate measure, which is not the same as mandating it. The test is appropriateness to the risk, and the reasoning matters more than the answer: a documented decision that a particular dataset is protected by other means is defensible, while an undocumented absence of encryption on a sensitive dataset is not.
We are a processor, not a controller. How much of this applies?
The security obligation applies directly to processors, which is one of the structural changes in this regulation, alongside the duty to assist the controller and to notify it without undue delay after becoming aware of a breach. A processor that assumed its exposure was purely contractual has misread its position.
What is the most common serious finding three months in?
Copies. Production data in test systems, extracts sitting in personal drives and mailboxes, reporting databases nobody classes as personal data processing, and backups of decommissioned systems that nobody can delete because nobody is sure what is in them. The perimeter is not where the exposure is.
What should we expect over the next twelve months?
Enforcement is likely to be driven by complaints and by the breach notifications that authorities have been receiving since May, rather than by proactive audits, so the first decisions will probably concern transparency, lawful basis and consent rather than security. Expect supervisory authorities to remain under-resourced and timelines to run long, which will be misread as leniency. Expect customer security schedules to harden faster than regulation does, particularly for suppliers outside Europe. Expect very little authoritative clarification of what "state of the art" means, which leaves documented reasoning as the only workable defence. And expect the first security-specific case to arrive from an organisation that reported its own breach and could not explain what it had done beforehand.
GDPR Security Compliance Audit — we assess the measures you can actually evidence, starting with the data flows, the logs and one honest restoration test, because that is the version of the story a customer or a regulator will eventually ask for.
