Quick Answer

GDPR Article 32 requires encryption, access controls, breach detection, patch management, and MFA. Coreitech implements all required technical measures for UK businesses. 0203 834 9728.

GDPR IT
COMPLIANCE
FOR UK BUSINESSES

GDPR Article 32 requires appropriate technical IT security measures. Coreitech implements and documents the controls the ICO expects — encryption, access management, breach detection, and patch management.

GDPR technical controls
Coreitech implements

Encryption at rest & in transit

BitLocker encryption on all devices, TLS for all data in transit, encrypted backups. GDPR Article 32 requires appropriate technical measures — encryption is explicitly listed.

Access controls & least privilege

Entra ID role-based access, MFA on all accounts, conditional access policies. Limiting who can access personal data to only those who need it is a core GDPR requirement.

Data backup & recovery

Tested backup procedures with documented RPO/RTO. GDPR requires ability to restore data availability after incidents — Article 32(1)(c).

Breach detection & incident response

24/7 SOC monitoring with documented incident response procedures. GDPR mandates 72-hour breach notification to the ICO — you need to detect breaches first.

Device management & remote wipe

Intune MDM enables remote device wipe if a laptop is lost or stolen — preventing personal data breach from lost hardware. Documented in your IT security policy.

Patch management & vulnerability management

Timely patching of all systems. Unpatched vulnerabilities that lead to a breach will be treated as failures of "appropriate technical measures" by the ICO.

Q.What IT measures does GDPR require?

GDPR Article 32 requires "appropriate technical and organisational measures" to ensure security appropriate to the risk. Key IT measures the ICO expects: encryption of personal data at rest and in transit, access controls limiting who can access personal data, tested backup and recovery procedures, patch management keeping systems up to date, MFA on systems accessing personal data, documented incident response procedures, and the ability to detect and report data breaches within 72 hours. Coreitech implements all of these as part of managed IT for UK businesses.

Q.Can the ICO fine my business for poor IT security?

Yes. The ICO regularly issues fines for data breaches caused by inadequate IT security. Common causes of ICO enforcement: failure to patch known vulnerabilities, no MFA on email accounts, poor backup practices leading to data loss, lack of encryption on devices, and phishing attacks that could have been prevented by email security. Fines can reach £17.5 million or 4% of global annual turnover. The ICO does not require a breach to issue an enforcement notice — they can act on systemic failures of data protection practice.

Q.Is Cyber Essentials certification enough for GDPR compliance?

Cyber Essentials covers the five technical controls most likely to prevent common cyber attacks (firewalls, secure configuration, access control, malware protection, patch management). These align closely with GDPR Article 32 requirements, so Cyber Essentials certification is strong evidence of appropriate technical measures. However, Cyber Essentials does not cover all GDPR requirements — data retention policies, subject access request processes, privacy notices, and consent management are outside its scope. Cyber Essentials + good data governance together demonstrate GDPR compliance.

Q.What should I do if my business has a data breach?

If you suspect a personal data breach: (1) Contain the breach — isolate affected systems, revoke compromised credentials. (2) Assess the risk — what data was involved, who might be affected, what is the harm potential? (3) Notify the ICO within 72 hours if the breach is likely to result in a risk to individuals' rights and freedoms. (4) Notify affected individuals if the breach is high risk to them. Document everything. Coreitech provides emergency cyber security incident response — call 0203 834 9728 immediately if you suspect a breach.

Get your IT GDPR-compliant
before the ICO comes knocking