77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Art. 32(1)(d) GDPR: a process for regularly testing. Why one check is not a process, and what a mock audit covers
Data Protection & Privacy

Art. 32(1)(d) GDPR: a process for regularly testing. Why one check is not a process, and what a mock audit covers

21 September 20268 min readBy CIVAC Redaktion
CIVAC

Art. 32(1)(d) GDPR requires “a process for regularly testing, assessing and evaluating the effectiveness” of technical and organisational measures. This article takes the three words process, regularly and effectiveness apart, sets Art. 24(1) sentence 2 and Art. 32(3) beside them, and describes what the mock audit in CIVAC contributes: criteria and evidence in, gaps with a corrective action out.

Point (d) in the text's own words

Art. 32(1) GDPR obliges the controller and the processor to “implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk” and then lists four measures included “inter alia as appropriate”. The fourth reads: “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.”

That is a different kind of measure from the three before it. Point (a) names pseudonymisation and encryption, point (b) the ability to ensure confidentiality, integrity, availability and resilience, point (c) the ability to restore availability in a timely manner. Those are properties of the processing. Point (d) is a measure about the measures: a process that looks at the other three.

Three words, three requirements

“Process”

A process has a defined sequence: who tests what, against which criteria, in what form the result is recorded, and what happens with a deviation. A check somebody carried out at some point, with the result sitting in an email, is a check. It is not a process, because nothing determines that and how it will be repeated.

“Regularly”

The Regulation names no interval. It requires regularity, and that is only evidenced once at least a second run has taken place and a third is scheduled. A single test, however thorough, does not satisfy the word. Which interval is appropriate depends, under Art. 32(1) first sentence, on the risk; a period in months is not in the text, and this article does not invent one.

“Effectiveness”

What is tested is not whether the measures exist but whether they work. A list with a tick next to “encryption” evidences existence. Effectiveness is only evidenced by a record that the encryption is actually active on the systems in question and held up under a test. That is why point (d) requires three activities and not one: testing, assessing and evaluating.

What Art. 24(1) sentence 2 adds

Art. 24(1) GDPR obliges the controller to implement measures “to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation”. The second sentence reads: “Those measures shall be reviewed and updated where necessary.” Point (d) of Art. 32 requires the process for testing; Art. 24(1) sentence 2 requires that testing is followed by an update where necessary. A process that finds gaps and does nothing with them satisfies the first sentence and misses the second.

What Art. 32(3) does not say

Art. 32(3) GDPR reads: “Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of this Article.” A certification is therefore an element of the demonstration, not the demonstration, and Art. 42(4) makes clear that it does not reduce responsibility. A certificate does not replace the process under point (d); it can be one of its results.

What the mock audit in CIVAC contributes

The CIVAC workspace contains a check that the code calls “audit readiness” and that performs a mock audit. It is not a process under point (d). It is a building block that supports the assessing and evaluating inside such a process. What it does is set out in the route that runs it.

  • Input is an existing audit of your own organisation, addressed by its short name: its criteria and the evidence filed against them. Another organisation's audit is not reachable; the query is bound to your own organisation.
  • The check is tied to a paid officer role: it runs only if the role that owns the audit is activated on the account.
  • The instruction to the model is to assess the way an external auditor would, to be strict but not to invent deficiencies: only what the data shows is assessed, and missing evidence is itself a gap.
  • Output is a summary, a readiness score from 0 to 100, a confidence in three levels and a list of at most forty gaps. Each gap carries a severity from five levels, a category, where possible a legal basis, the criterion or missing evidence it refers to, and a concrete corrective action.
  • Each gap becomes a task with an owner in one click, carrying the recommendation and legal basis; the gap is set to “remediating” and linked to the task.

In the words of point (d): the testing takes place in the audit whose criteria and evidence the mock audit reads. Assessing and evaluating is what the mock audit does, with the readiness score and the gaps. The update under Art. 24(1) sentence 2 begins the moment a gap becomes a task. Regularity does not arise in the check but in the recurring task that schedules the next audit run, and in the check being run again each time.

What the check expressly is not

It does not test systems. It reads what was filed in the audit as evidence and assesses whether it would satisfy an auditor. Evidence that is wrong but looks complete is not recognised as wrong. Testing effectiveness on the systems themselves remains the work of the people running the audit. And the confidence in three levels is a statement about the reliability of the assessment, not about the legal position.

Where this article ends

Which testing interval is “regular” for your processing within the meaning of Art. 32(1)(d) GDPR, whether your measures are appropriate to the risk, and when an update under Art. 24(1) sentence 2 becomes “necessary” are questions that require a legal examination of the individual case. CIVAC is not a law firm and does not provide legal advice. This article reproduces the wording of the Regulation and the mechanism of a check; the assessment of your case belongs with your data protection officer or with someone authorised to give it.

Frequently asked questions

Does Art. 32 GDPR name a testing interval?

No. Point (d) requires “a process for regularly testing” without naming an interval. What is appropriate depends, under Art. 32(1) first sentence, on the risk of the processing.

Is a one-off test of the measures enough?

No. Regularity presupposes repetition, and a process presupposes a defined sequence. A single test with no scheduled repetition satisfies neither word.

Does a certificate replace the process under point (d)?

No. Art. 32(3) GDPR allows an approved certification mechanism to be used “as an element” of the demonstration, and Art. 42(4) makes clear that a certification does not reduce responsibility.

Is the mock audit in CIVAC a process under Art. 32(1)(d) GDPR?

No, it is a building block. It assesses the criteria and evidence of an existing audit and returns gaps with a corrective action. The process arises from the recurring task that schedules the audit run, the check on every run, and the tasks the gaps turn into.

What does the readiness score from 0 to 100 mean?

It is the model's estimate of how ready the audit would be for a real inspection, with 100 standing for audit-ready. It is an indication based on the evidence filed, not a statement about the legal position and not the result of an external auditor's inspection.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles