Back to blog
GDPRPublished on July 6, 20269 min read

GDPR and endpoints: the measures regulators expect

GDPR mandates appropriate security measures. The concrete translation on endpoints: encryption, MFA, lock, access management, updates and evidence.

GDPR Article 32 requires 'appropriate technical and organizational measures' to ensure the security of personal data, taking into account the state of the art and the risks. The text stays deliberately general: it names neither BitLocker, nor MFA, nor an update window. That generality confuses SMBs, who don't know how far to go. Yet on endpoints, the expectations of regulators are well identified and documented in their IT-hygiene guidance, and they converge on a short, recognizable list of controls that any SMB can put in place.

The challenge is twofold: put these measures in place, and be able to prove it. Because in case of an audit or a data breach, the organization must demonstrate its diligence. A measure in place but undocumented counts for little in front of an auditor. Here is the concrete translation of Article 32 on endpoints, a device-loss scenario, the mistakes that worsen the risk, and how to produce the associated evidence.

The measures expected on endpoints

  • Encryption of devices and removable media, so hardware loss is not a breach.
  • Strong authentication (MFA) and automatic session lock after inactivity.
  • Patch management and up-to-date antivirus, to reduce the attack surface.
  • Control and logging of access to personal data.
  • Ability to remotely wipe a lost or stolen device.
Article 32 translated into concrete, deployable Intune controls.

The key principle: proportionality and state of the art

Article 32 calls for measures proportionate to the risk and aligned with the state of the art. In practice, this means laptop encryption, MFA and updates are no longer optional: they have become the expected standard. Not having them in place risks a breach being characterized as negligence, which weighs heavily on the amount of any sanction and on the organization's reputation.

The data-breach case

In case of a lost or stolen device, the central question is: was the data protected? An encrypted and locked laptop turns a potentially notifiable breach into a non-event, because the data stays inaccessible. Regulators indeed treat robust encryption as a major mitigating factor, potentially avoiding notification to the affected individuals, provided the keys were not compromised.

The step-by-step approach

  1. 1Map the devices that process personal data.
  2. 2Deploy encryption (BitLocker, FileVault) with key backup.
  3. 3Roll out MFA and enforce automatic session lock.
  4. 4Set up automatic updates and up-to-date antivirus.
  5. 5Configure remote-wipe capability for devices.
  6. 6Document everything in a dated report, mapped to Article 32.

A concrete example: the laptop left on the train

A sales rep leaves their work laptop on a train. It holds a client file with names, addresses and purchase histories — personal data. Without encryption, the company must assume this data is potentially accessible, assess the risk to individuals, and probably notify the regulator within 72 hours, possibly even informing the affected clients.

With a device encrypted by BitLocker, automatically locked and whose key has not leaked, the scenario changes radically: the data stays unintelligible to whoever finds the machine. The company documents that encryption was active at the moment of loss, triggers a remote wipe as a precaution, and this evidence can be enough to avoid notifying the affected individuals. The same loss becomes a minor hardware incident, resolved by ordering a replacement laptop, rather than a regulatory crisis with letters to send and reputational fallout to manage.

Lock, wipe and the minimization principle

Encryption protects data at rest, but it doesn't do everything. Two complementary measures clearly reduce the risk if a device is lost or compromised, and they are expected under Article 32 as basic reflexes.

  • Automatic session lock after a few minutes of inactivity, so a device left open doesn't stay exposed.
  • A requirement for a strong code or password at unlock, on desktops and mobile devices alike.
  • Remote wipe of a lost or stolen device, which removes the work data from a distance.
  • Logging of access to personal data, to reconstruct who viewed what in case of an incident.
  • Limiting local administrator rights, to reduce the impact of a compromised account.

These measures fit a risk-minimization logic: the less data and privilege a device exposes, the less serious its loss. Combined with encryption, they form a defense in depth that directly answers the proportionality requirement of Article 32, while staying simple to deploy through Intune across the whole fleet.

The mistakes that worsen the risk

  • Having measures but no dated record: impossible to prove diligence during an audit.
  • Encrypting laptops but leaving USB keys unencrypted: the leak goes through removable media.
  • A session lock that's too slow: a device left open stays accessible to a third party.
  • No remote-wipe capability: a lost device stays a permanent risk.
  • Treating compliance as a fixed state: it drifts without regular review.

Prove your diligence with AuPoint

AuPoint maps each deployed control to GDPR Article 32 and produces a PDF-exportable, dated compliance report listing the measures in place and those still to complete. In case of a regulator audit or a client questionnaire, you demonstrate your diligence without starting from scratch or reconstructing the history by hand. The report translates a technical configuration into language a data protection officer or a lawyer can understand.

The deployment itself is safe: a plain-language catalog, impact preview before applying, the 'exclude me' option and break-glass account to avoid any lockout, one-click reversibility. You cover GDPR requirements on endpoints without pulling in an expert, and you track compliance drift continuously — a device that falls out of compliance is spotted before it becomes the weak link during an incident. This turns GDPR from a paper exercise into a live, verifiable state of your fleet.

The GDPR report maps each control to Article 32 and provides dated evidence.

FAQ

Does encryption exempt me from reporting a breach?

Not automatically, but robust encryption, with uncompromised keys, can render the data unintelligible to a third party and thereby avoid notification to the affected individuals. It's a major mitigating factor recognized by regulators, and one to document precisely.

Does GDPR mandate specific tools?

No. Article 32 mandates proportionate security objectives, not products. Microsoft Intune and Conditional Access let you meet them on endpoints, provided they are correctly configured and documented. What an auditor checks is the effectiveness and the evidence, not the product name.

How do I prove the measures were in place before an incident?

Through a dated report and the activity history. AuPoint keeps a record of the deployed controls and their dates, which lets you demonstrate the measure was active at the relevant time, a decisive point in front of a supervisory authority.

Connect your tenant to AuPoint and get your endpoint GDPR score in a few minutes — with a clear plan of the controls to enable and dated, exportable evidence to show a regulator. Start free today.

Secure your tenant in 15 minutes

Free trial