The classic trap
Recital 83 sets the reading grid for Article 32: security is not a universal checklist but a trade-off between state of the art, implementation costs and risks specific to the processing. The CNPD and CNIL regularly sanction controllers who apply a generic baseline (antivirus, password, backup) without documenting why those measures are appropriate to the actual risks: destruction, loss, alteration, disclosure, unlawful access. Without a documented risk assessment, any breach becomes a presumption of non-compliance, because the controller cannot demonstrate its ex ante reasoning.
The 'appropriate' test: how to argue it before the CNPD
To turn Recital 83 into opposable evidence, your risk analysis must articulate four dimensions per processing activity:
- State of the art: explicit reference to ANSSI, ENISA, ISO 27001/27002, NIST CSF, CIS Controls at decision date.
- Implementation cost: budget figures for selected and rejected measures, with documented trade-off rationale.
- Nature of the data: categorisation (Article 9, banking data, children's data, national identifiers) which raises the required level.
- Risk scenarios: accidental destruction, ransomware, internal exfiltration, mis-sent emails, unlawful access by a processor, scored by probability and severity.
Encryption is explicitly named in the recital: its absence on sensitive databases, backups or mobile endpoints becomes almost indefensible without written justification.
How Luxgap automates this risk
Our Luxgap Risk-Based Security Justifier turns the vague obligation of appropriate measures into an opposable argumentation file, generated automatically for each processing activity. The tool cross-references your Article 30 register, your system mapping (Microsoft Defender, Azure Sentinel, CrowdStrike, Wazuh) and ANSSI/ENISA/ISO 27001 frameworks updated monthly to produce the written justification the CNPD expects during an inspection, without the DPO or CISO having to draft a single line.
- Automatically scores each processing activity on the four axes of Recital 83 (state of the art, cost, nature of data, risk scenarios) with a reproducible numeric score.
- Detects gaps between technical measures actually deployed (Defender scans, AD configuration, BitLocker encryption, TLS) and the level required for the data category at stake.
- Generates a per-processing justification report, written in legal language, citing applicable standards and the cost/risk trade-off retained.
- Sends real-time alerts when a new processing activity appears in Odoo, M365 or Salesforce without security measures proportionate to its risk level.
- Produces a cryptographically sealed, time-stamped PDF, opposable to the CNPD, materialising the controller's ex ante reasoning.
- Re-evaluates compliance with the state of the art every quarter, as soon as an ANSSI or ENISA standard is revised.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real processing activities, with a free 48h white audit to measure your exposure before any engagement.