Data Protection Regulation

GDPR (General Data Protection Regulation)

Article 32 requires appropriate technical measures to protect personal data: access control is one of the clearest ways to demonstrate it.

What does GDPR require of access control?

The UK/EU General Data Protection Regulation governs how personal data is collected, processed, and protected. Article 32 specifically requires organisations to implement measures appropriate to the risk, including the ability to ensure ongoing confidentiality and to restrict access to personal data on a need-to-know basis.

In practice, this means being able to answer a deceptively hard question at any moment: who currently has access to this personal data, why, and when was that last reviewed?

GDPR deliberately doesn't prescribe the how: it doesn't name role-based versus attribute-based models, mandate a specific MFA threshold, or set a review cadence. It leaves that to the organisation, provided the choice was risk-based and can be evidenced under Article 5(2)'s accountability principle. In our experience, that evidentiary bar is where UK ICO enforcement action most often actually lands: not that access was too broad in isolation, but that nobody could show when it was last reviewed, or why it was granted in the first place.

How IAM Tech helps

We design access models built on least-privilege and need-to-know principles, and build the audit trail that makes “who accessed what, when” a demonstrable fact rather than a theoretical policy.

  • Least-privilege access models scoped to actual business need
  • Access review and certification cycles with a documented trail
  • Clearer access visibility to support data subject access requests (DSARs)
  • Segregation-of-duties controls to prevent unauthorised data combination
See Identity Governance →

See our full approach to IAM for Insurance →

Common questions

Does GDPR require multi-factor authentication (MFA)?

Not by name. Article 32 requires measures appropriate to the risk, not a fixed control list. For systems processing special category data or personal data at scale, UK Information Commissioner's Office (ICO) guidance treats MFA as close to a baseline expectation, and not having it invites the question of why a lower-friction control was chosen instead.

How often does GDPR require access reviews?

No fixed cadence is set in the regulation. What matters is a demonstrable, risk-based cycle. Most programmes we work on settle on quarterly reviews for high-risk data and privileged access, and annual reviews for lower-risk day-to-day access, run consistently enough to survive an audit.

Want to know where you stand?

Take the free 2-minute IAM Health Check, or talk to us directly about your GDPR requirements.

Talk to us
Talk to us