GDPR technical measures for secure company data
An unlocked laptop, a shared password for corporate email, or an archive that cannot be restored in time—any of these is enough to turn a routine technical oversight into a personal data incident. GDPR technical measures are not merely a formality for the documentation folder; they constitute the practical safeguards that restrict access, mitigate damage in the event of an attack, and enable business continuity following a system failure.
For small and medium-sized enterprises, the subject often seems overly broad. Not every organization possesses an in-house cybersecurity team or complex infrastructure. However, the regulation does not mandate a uniform set of technologies for everyone. Instead, it requires measures to be tailored to the specific risks, the nature of the data, operational workflows, and the actual consequences of a potential breach.
What GDPR Technical Measures Require
Article 32 of the GDPR focuses on the security of processing. In practice, an organization must be able to safeguard the confidentiality, integrity, availability, and resilience of the systems processing personal data. It must also be capable of restoring access to data within a reasonable timeframe following a technical or physical incident.
This entails more than just antivirus software and periodic file backups. The measures must function as a cohesive system: users are granted only the access rights they need, devices are kept up to date, data is backed up, and unusual events are detected and investigated in a timely manner.
The approach is risk-based. A medical practice handling health data has a different risk profile than a commercial company holding only limited contact details. A company with remote employees, cloud applications, and access to client systems must secure more entry points than an office where everyone operates on a managed internal network. The crucial question is not "Which product should we buy?" but rather "What data could be affected, and what would happen if the security measures failed?"
Access Control: The First Line of Practical Defense
Many incidents do not begin with a sophisticated attack but rather with excessively broad access rights. An employee might have access to the entire client database simply because it was convenient when they were hired. A former colleague might still be able to log into the cloud storage. A shared account might be used by multiple people, making it impossible to determine who performed a specific action when a problem arises.
The correct model is access based on role and business necessity. The finance team should not automatically have access rights to HR folders, nor should an external contractor be granted permanent administrative access for a temporary task. Any change in job role, granting of new access, or employee departure must trigger a clear process for reviewing access rights.
Multi-factor authentication is one of the most effective measures in this regard. A password can be stolen via phishing, reused in another breach, or simply shared inadvertently. While a second factor does not eliminate the risk entirely, it makes unauthorized access to email, cloud applications, VPNs, and administrative panels significantly more difficult.
Other best practices include using individual accounts, enforcing a strong password policy, and implementing a secure process for administrator profiles. Administrative rights should be granted only when necessary, rather than as a default workplace setting. This limits the scope of potential damage if a device or account is compromised.
Data and Device Encryption
Encryption plays a different role depending on where the data is located. Data in transit must be transmitted over secure connections. For data at rest, one must consider how laptops, servers, archives, and cloud storage are protected.
The most relatable example is the work laptop. If it is lost or stolen, disk encryption reduces the likelihood of files being read by a third party. Without encryption, physical possession of the device could grant access to saved documents, local archives, downloaded reports, and client information.
Encryption is not a substitute for access control. If a user with valid credentials is tricked into revealing their login details, disk encryption will not solve the problem. It is merely one component of a multi-layered defense strategy that also includes multi-factor authentication, device management, and activity monitoring.
When using cloud services, it is essential to verify what the provider encrypts, how keys are managed, where data is stored, and what options exist to restrict sharing. A setting that allows a public link to a folder containing personal data can undermine the platform's otherwise robust security measures.
Backups are an availability measure, not just a routine archiving habit
Ransomware attacks, server failures, accidental file deletion, or synchronization errors can all block access to critical data. GDPR views the ability to perform timely recovery as a security requirement, as a loss of data availability can impact the rights of the individuals whose data is being processed.
An effective backup strategy includes a separate copy that cannot be easily encrypted or deleted along with the primary environment. Simply having an indication that a backup job is running is insufficient; actual recovery of files, systems, and critical services must be tested periodically.
In this context, businesses need to make two clear decisions. The first is determining how much data loss is acceptable in the event of an incident. The second is determining how long operations can continue without a specific system. These answers dictate the backup frequency, retention period, and the need for redundant infrastructure. These parameters often differ for accounting systems, CRM platforms, and file servers.
Updates, Endpoint Protection, and Monitoring
Unapplied updates leave known vulnerabilities exposed. This applies to operating systems, browsers, firewalls, VPN services, server applications, and often-overlooked devices such as network printers or NAS systems. Update management requires a designated owner, a schedule, and verification that installations were successful.
Endpoints are particularly critical, as employees use them to read emails, open files, and handle personal data. Centrally managed device protection helps track antivirus status, disk encryption, operating system versions, and the presence of risky settings. In the event of a lost work phone or laptop, the ability to remotely lock or wipe the device can be crucial.
Monitoring adds context. Unusual logins from another country, mass file downloads, multiple failed login attempts, or sudden privilege escalation are signals that must reach someone capable of taking action. Collecting logs is insufficient on its own if no one reviews them and there is no escalation procedure in place.
Testing and Verifiable Controls
Technical measures must be verified rather than assumed to be functional by default. Periodic access reviews reveal whether inactive accounts remain in the systems. Recovery tests prove the usability of backups. Vulnerability scanning and configuration reviews identify issues before they can be exploited. It is important for the organization to maintain evidence of these controls: backup reports, access rights review logs, test results, a list of managed devices, and documentation of incident responses. This supports not only GDPR compliance but also faster decision-making when an actual issue arises.
Not every check needs to be a complex audit. For a small company, a well-maintained monthly control process can be more valuable than a one-off major project that lacks ongoing maintenance. In cases of higher risk, sensitive data categories, or complex environments, it is prudent to incorporate external testing and specialized expertise.
How to get started without haphazard investments
The most useful first step is to create a map of data and systems. Where is personal data stored? Who has access? Which devices process it? What cloud services are used, and do external vendors have access? Risks can then be prioritized based on their likelihood and impact on operations.
Typically, the initial priorities include eliminating shared accounts, enabling multi-factor authentication, encrypting mobile devices, verifying backups, and implementing regular updates. This does not mean that all other measures can be postponed indefinitely; rather, it means directing budget and effort toward addressing the gaps with the greatest potential impact.
The technical environment changes with every new employee, application, and device. Therefore, the best defense is not a one-time checklist, but a disciplined process that makes security measurable, verifiable, and part of the company's normal operations.


