Filers who named this exact article number in their own text. It is their sentence, not our reading — and not a causal claim.
| Who | Country | What they wrote |
|---|---|---|
| MyData-TRUST | BE | ment (along with Annex II's description of security measures) could arguably be taken to cover assistance with the exporter's own Art.32 security obligations also, as required by Art.28(3)(f), but the only explicit reference in Clause 8.6(d) is to notification ↗ |
| Bundesrechtsanwaltskammer | DE | for the natural persons concerned are hardly higher than for any other business correspondence. The protection re- quirements of Article 32 GDPR are correspondingly lower in such a case. A further limitation of the protection requirements that are to be imple ↗ |
| Global Data Alliance | BE | order data transfers to make them as effective as possible. This also clashes with the controller’s and processor’s obligation of Article 32 of the GDPR to “develop appropriate technical and organizational measures to ensure a level of security appropriate to ↗ |
| ZVEI e. V. - Verband der Elektro- und Digitalindustrie | DE | sonders wichtiges datenschutzrechtliches Instrument darstellt. Dieser herausragenden Stellung sollte über die einfache Nennung in Artikel 32 Ab- satz 1 lit. a) DSGVO hinaus Rechnung getragen werden. ↗ |
| Cloudflare | US | easures that rely on cross-border data transfers to make them as effective as possible. This directly clashes with the obligation Article 32 GDPR places on data controllers and processors to “develop appropriate technical and organizational measures to ensure ↗ |
| EDRi European Digital Rights | ES | ech firms, lacking control and specific knowledge over the data they hold. Which also casts doubt on their ability to comply with article 32 (appropriate measures to safeguard the data processed). There is also a worrisome trend of data controllers referring t ↗ |
| Bitkom e.V. | DE | allow for profiling for other purposes (than the provision of a service) even with the explicit consent of the user. Article 32 (1) Data Act obliges providers of data processing services to take “all adequate technical, organizational and legal measures” to pr ↗ |
| ESOMAR | NL | on the principles of privacy by design and privacy by default, Articles. 33 and 34 on governing the management of a data breach, Article 32 on security, etc.) the GDPR’s risk- based approach means that data controllers are encouraged to implement protective m ↗ |
| Verband der öffentlichen Wirtschaft und Gemeinwirtschaft Österreichs (VÖWG) | AT | iv wäre zu präzisieren bzw. einzugrenzen, z.B. dahingehend, dass halbjährliche/jährliche Anfragen jedenfalls als exzessiv gelten. Art. 32: Die Aufnahme einer Regel betreffend der Speicherfristen für Zugriffsprotokolle vergleichbar mit dem §14 des DSG 2000 soll ↗ |
| BSA | The Software Alliance | BE | istent with the GDPR, in particular where they are deemed necessary to fulfil the obligations of controllers and processors under Article 32 of the GDPR. All in all, a unified response by the EDPB and the European Commission expressing opposition to occasional ↗ |
| Oplysningsforbundet May Day | DK | å en central server. I et databeskyttelsesperspektiv forhindrer denne proces dataminimering jf. GDPRs artikel 25, stk. 2 og GDPRs artikel 32, stk. 1.a, fordi oplysningerne fra passet gemmes, og billederne opbevares på en server, der tilhører leverandøren af Mi ↗ |
| Computer & Communications Industry Association's (CCIA Europe) | BE | ereby undermining industry’s efforts to ensure the integrity of EU personal data. This would also contradict the obligation under Article 32 of the GDPR which mandates controllers and processors to take “into account the state of the art” and to “implement app ↗ |
| Avvocato | IT | ica del testo del Regolamento UE 2016/679: 1) il superamento del contrasto tra principio di atipicità delle misure contenuto nell'art. 32 obbligo in capo al titolare e al responsabile del trattamento di adottare misure tecniche ed organizzative adeguate - e di ↗ |
| Federation of Austrian Industries | AT | understand that the GDPR does not have a general approach regarding “adequacy” but only refers to it in certain provisions (e.g. Art 32 GDPR). We would 10 appreciate if the scalability of obligations is used either in general in the application of GDPR (espec ↗ |
| AUSTRIAN FEDERAL ECONOMIC CHAMBER | AT | umstances can pose problems for data controllers (e.g., a surge in data subject rights). However, some obligations in GDPR (e.g., Art 32 GDPR) involve the need for extensive interpretation in practice. Without specific advice from the local DPA, this leaves a ↗ |
| Insurance Ireland | IE | ctored into their onboarding and assurance processes for suppliers. Other members noted that in relation to the obligations under Article 32(1)(d) GDPR, guidelines on what is an acceptable list of technical and ↗ |
| Anonos Inc. | US | purpose of the processing are processed.” 4 • Reduce the Risk of Data Breach Liability Obligations and Liability a. Article 32 explicitly recognises Pseudonymization and encryption as measures to be considered when“[t]aking into account the state of the art, t ↗ |
| noyb | AT | conduct for which a respondent has already been fined within the Union.88 Article 32 - Enforcement of other remedies 1. Without prejudice to any other instruments, a lead supervisory authority may request another supervisory authority to use its corrective po ↗ |
| Julia O'Toole | FR | regulation, you would do more than any other move you can possibly make to genuinely protect personal data. Our feedback on GDPR Article 32.4: In most organizations, it is impossible for the controller or processor to control their data because they do not ha ↗ |
| Pinsent Masons | IE | ssue is how lower and higher level administrative fines are distinguished, and whether non-compliance of a specific Article (e.g. Article 32) should always be considered an infringement or non-compliance with an Article 5 Principle. Such an interpretation woul ↗ |
| Digitale Gesellschaft e.V. | DE | ers must be obliged to implement data protection by design and by default mechanisms (Article 25) as well as security mechanisms (Article 32) into ICT systems to enable end-users to protect their fundamental rights and freedoms, and help controllers and proces ↗ |
| Local Government Denmark | DK | munernes opgavevaretagelse, herunder håndtering af persondata, allerede i vidt om- fang er detaljeret reguleret ved lov. - Ifølge artikel 32 skal kommunerne i deres valg af passende sikkerhedsfor- anstaltninger i forhold til deres behandlinger af data tage hen ↗ |
| Federation of Austrian Industries (Industriellenvereinigung) | AT | data protection law, as unauthorised disclosure of personal data may occur due to the US-CLOUD Act (see Art 32 GDPR). Furthermore, the legal situation also poses a legal risk for US cloud providers with branches within the EU, because a court order from a thir ↗ |
| Council of the Notariats of the European Union (CNUE) | BE | actors - Classification as subcontracting data controller – joint data controller - Subcontractor’s obligations Art 32: an obligation to implement technical and organisational measures guaranteeing a level of security appropriate to the risk ↗ |
| BVPA Bundesverband professioneller Bildanbieter e.V. | DE | sehr hilfreich. b) Fotografien und Bildagenturen als AuMraggeber von AuMragsverarbeitern Die sich aus Art. 28 DSGVO (AVV) i.V. m. Art. 32 DSGVO (TOM) und ggf. zusätzlich aus Art. 44ff DSGVO (Driostaatentransfer) sowie aus Art. 30 DSGVO (Verarbeitungsverzeichnis ↗ |
| — | that are not EU? Non-EEA controllers and processors need more explanations. The wording of many Articles are vague. For example, Article 32: “shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the ri ↗ | |
| Insurance Europe | BE | proposed in the draft guidelines. This approach would be in line with the spirit of the GDPR and in particular with the letter in Article 32 and recital 83. The balancing of interests in the section on lawfulness (page 15): The final guidelines should be align ↗ |
| Österreichische Bundesarbeitskammer | AT | would normally not be considered as depriving the end-user of a genuine choice…“) • Art und Umfang der Protokollierungspflichten (Art 32) sind näher zu regeln (nicht zuletzt, um Datenquellen und algorithmische Entscheidungen nachvollziehbar zu machen). • Die G ↗ |
| — | e, security is one (the last) of the principles relating to the processing of personal data listed in article 5. But in fact ONLY article 32 concerns security of processing as such (and such is its title). So most organisations concentrated and still concentra ↗ |
Source: public consultation submissions and position papers. n = 29 mentions; counted as a literal reference to the article number.