When Sweden's IMY fined Miljödata $183,000 for security failures that exposed 2.2 million people's data, they cited two specific gaps: inadequate software deployment checks and missing real-time monitoring. Both violations directly relate to GDPR Article 32(1) requirements for "appropriate technical and organisational measures."
This checklist translates Article 32(1)'s principles into verifiable controls. Each item addresses a requirement your auditors will test and your regulators will expect during breach investigations.
What This Checklist Covers
Article 32(1) mandates security "appropriate to the risk" when processing Personally Identifiable Information. That phrase offers flexibility but no protection during enforcement. This checklist covers the five control categories regulators scrutinize:
- Pre-deployment security validation
- Continuous monitoring and detection
- Encryption at rest and in transit
- Access control and authentication
- Security testing and improvement cycles
Use this for quarterly self-assessments, vendor audits, or board reporting. Each item should have a clear owner and evidence trail.
Prerequisites
Before starting this checklist, you need:
Data inventory: A current register of what Personally Identifiable Information you process, where it lives, and who accesses it. You can't secure what you haven't cataloged.
Risk assessment: A documented analysis of threats to that data, scored by likelihood and impact. Article 32(1) requires measures "appropriate to the risk," so you must know the risk first.
Defined roles: Clear assignment of who owns each control, who tests it, and who reports exceptions. Security by committee is security by nobody.
Good looks like: A spreadsheet or GRC platform showing data flows, risk scores, and control owners, updated within the past 90 days.
Checklist Items
1. Software deployment validation
□ Every new software installation undergoes security review before production deployment, including third-party updates and patches.
□ Review includes: vulnerability scanning, configuration baseline checks against CIS Foundations Benchmark or equivalent, and validation that default credentials have been changed.
□ Deployment approval requires sign-off from both IT operations and security, documented in your change management system.
Good looks like: Change tickets showing security review completion, scan results attached, and dual approval within the past 30 days for your most recent deployment.
2. Real-time intrusion detection
□ Automated monitoring covers all systems processing Personally Identifiable Information, with alerts configured for unauthorized access attempts, privilege escalation, and lateral movement.
□ Monitoring tools generate alerts within 15 minutes of suspicious activity, not batch reports the next morning.
□ Someone receives and triages these alerts 24/7, even if you're using a managed detection service.
Good looks like: Alert logs showing detection events, response actions, and closure times. Test by simulating an unauthorized login; your system should flag it and someone should investigate within your defined SLA.
3. Encryption at rest
□ All databases and file stores containing Personally Identifiable Information use encryption meeting current standards (AES-256 or equivalent).
□ Encryption Key Management follows documented procedures that separate key storage from data storage.
□ You've tested your ability to prove encryption is active; it's not enough to check a configuration box.
Good looks like: Configuration screenshots showing encryption enabled, key rotation logs from the past quarter, and a successful decryption test performed by someone other than the person who set it up.
□ All Personally Identifiable Information moving between systems uses TLS 1.2 or higher with strong cipher suites.
□ You've disabled older protocols (SSL, TLS 1.0/1.1) that auditors will flag as inadequate.
□ Certificate management includes automated expiration alerts and a documented renewal process.
Good looks like: Network scans showing only approved protocols active, certificate inventory with expiration dates, and evidence you renewed before expiration in your last cycle.
5. Access control and authentication
□ Every account with access to Personally Identifiable Information requires multi-factor authentication, no exceptions for "trusted" networks or legacy systems.
□ Access follows least privilege: users can only reach the specific data their job requires, verified through quarterly access reviews.
□ Privileged accounts (admin, root, service accounts) are monitored separately with stricter controls and logging.
Good looks like: Identity provider logs showing MFA enrollment rates at 100% for in-scope users, access review sign-offs from data owners, and privileged access management reports showing session recordings.
6. Automated security testing
□ Vulnerability scanning runs at least weekly on all systems processing Personally Identifiable Information, with critical findings remediated within your defined SLA.
□ Annual penetration testing by qualified third parties covers your data processing environment.
□ You track Mean Time to Remediate for security findings and report trends to leadership.
Good looks like: Scan schedules showing completion dates, remediation tickets with closure evidence, and a penetration test report from the past 12 months with a management response to each finding.
7. Incident detection and response
□ Your Computer Security Incident Response Team has documented playbooks for data breach scenarios, tested within the past year.
□ Log retention meets regulatory requirements (typically 12 months minimum for systems processing Personally Identifiable Information).
□ You can reconstruct what happened during a security event using your logs, not guesswork.
Good looks like: Tabletop Exercise documentation showing breach scenario walk-throughs, log management reports proving retention compliance, and a successful log query demonstrating you can trace a specific data access event.
8. Vendor security validation
□ Every vendor processing your Personally Identifiable Information undergoes security due diligence before contract signature, including SOC 2 review or equivalent.
□ Data Processing Agreements explicitly assign GDPR obligations and include audit rights.
□ Annual vendor security reviews verify controls remain effective.
Good looks like: Vendor risk register showing assessment dates and scores, signed Data Processing Agreements on file, and evidence of your most recent vendor audit or attestation review.
Common Mistakes
Confusing compliance with security: Checking boxes on this list doesn't mean you're secure; it means you've met minimum regulatory expectations. Miljödata's breach happened despite likely having some monitoring in place. "Real-time" means alerts that trigger action, not dashboards someone checks when convenient.
Treating Article 32(1) as IT's problem: Security measures require technical implementation, but appropriate controls require business context. Your IT team can't determine what's "appropriate to the risk" without input from legal, compliance, and business owners who understand data sensitivity.
Assuming small breaches fly under the radar: The Miljödata fine came from failures the regulator could verify, not from breach size. IMY specifically called out missing software checks and monitoring gaps. Regulators look for negligence, and inadequate controls are negligence regardless of whether you got breached.
Skipping the evidence trail: During investigations, "we have a process" means nothing without proof you followed it. Every control on this checklist should generate artifacts: tickets, logs, reports, sign-offs. If you can't show it, you didn't do it.
Next Steps
Month 1: Assign an owner to each checklist item and document current state. You'll likely find gaps; that's the point.
Month 2: Prioritize gaps by risk score and regulatory exposure. Fix the items that would appear in a regulator's report first.
Month 3: Implement fixes and collect evidence. Update your risk register to reflect improved controls.
Ongoing: Build this into quarterly reviews. Article 32(1) requires security "appropriate to the risk," and risk changes. Your controls must evolve with your data processing activities.
The $183,000 penalty Miljödata paid is the floor, not the ceiling. GDPR fines can reach €20 million or 4% of global revenue, whichever is higher. But the regulatory penalty is rarely the largest cost. Factor in breach notification expenses, customer remediation, legal fees, and reputation damage, and inadequate controls become existentially expensive.
Your goal isn't perfection. It's demonstrable diligence that would survive regulatory scrutiny during your worst week. This checklist gives you the framework to prove it.




