GDPR security outcomes
Download this document free
Get this document with your free trial. Choose from the full Complyzard library.
Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.Document information
This guidance describes a set of technical security outcomes that are considered to represent appropriate measures under the GDPR.
Adapted edition
- Document type
- Reference Guide
- Format
- DOCX
- Pages
- 7
- Language
- English
- Version
- 1.0
- Updated
- 2026-09-16
- Category
- Information security
- Licence
- Open Government Licence v3.0
Description
This guidance describes a set of technical security outcomes that are considered to represent appropriate measures under the GDPR for organisational planning, review and training. NCSC guidance is advisory and should be applied to the organisation's own risks and obligations.
Contents
- What does the GDPR say about security?
- Data protection and security of processing
- Accountability and our responsibility as data controllers
- What are appropriate technical and organisational measures?
- Why security outcomes?
- Aims
- Outcomes
- A) Manage security risk
- A.1 Governance
- A.2 Risk management
- A.3 Asset management
- A.4 Data processors and the supply chain
- B) Protect personal data against cyber attack
- B.1 Service Protection Policies and Processes
- B.2 Identity & Access Control
- B.3 Data Security
- Source links
Source and licence
National Cyber Security Centre
AttributionNational Cyber Security Centre, “GDPR security outcomes” (17 May 2018), reused under the Open Government Licence v3.0.
ChangesAdapted 16 September 2026: converted the official HTML article into neutral text-only DOCX and PDF editions. Preserved article headings, paragraphs, lists and plain-text source-link destinations; normalized web whitespace and typographic punctuation; omitted site navigation, topic and download cards, images, logos, scripts, styles and page furniture.
Version history
- v1.016/09/2026