Data protection

GDPR Penetration Testing

Article 32 testing of technical measures for US organizations that handle the personal data of people in the EU.

Overview

How testing supports GDPR

GDPR Article 32 requires appropriate technical and organizational measures, and — unusually explicit for a privacy law — a process for regularly testing, assessing and evaluating their effectiveness. For US organizations that market to or monitor people in the EU, that obligation applies regardless of where the company sits. Penetration testing is the most direct way to evidence the regular testing Article 32 names.

Where it maps

What a test evidences

A single engagement produces evidence across these areas of GDPR.

Article 32(1)(d)

The regular testing of technical measures the regulation explicitly requires.

Data-exposure paths

Where personal data could be reached — the exposures that turn into reportable breaches.

Security of processing

Evidence that the measures protecting personal data are effective, not just documented.

Breach-readiness

Findings that reduce the likelihood and impact of the breaches Article 33 would have you report.

One engagement

Evidence for every framework at once

Most organizations answer to several frameworks, not one.

We scope a single penetration test so its findings and evidence serve GDPR alongside the other standards your auditors, customers and insurers ask about — instead of running overlapping engagements for each.

gdpr-evidence.pdf
FindingSeverityMaps to
Cross-tenant data accessCriticalGDPR
Over-privileged accessHighGDPR
Weak session handlingMediumGDPR
Questions

GDPR testing, answered

Does GDPR apply to a US company?

It can. If you offer goods or services to, or monitor the behavior of, people in the EU, Article 3 extends GDPR to you regardless of where you are based — and Article 32 comes with it.

How does testing help with GDPR?

Article 32 explicitly requires a process for regularly testing the effectiveness of technical measures. A penetration test is the standard way to satisfy and evidence that requirement.

Testing for GDPR?

Tell us the framework and the deadline. We scope to the evidence your assessor needs.