← All GDPR articles

Art.32

Security of processing

Mandates appropriate technical and organizational measures — encryption, access control, secrets management — proportional to risk.

Why it matters for SaaS exits

Art.32 is the most technically testable article — a buyer can verify HTTPS, certificate validity, and mixed content in seconds. Failing these basics signals to buyers that deeper security practices (secrets management, access controls) are likely also weak. A site without HTTPS in 2026 is an immediate deal-breaker.

What we scan for

We check three things: (1) Is the site served over HTTPS? (2) Is the SSL certificate valid and not expired? (3) Are there mixed-content warnings (HTTP resources on HTTPS pages)? Each failure is a separate Art.32 finding.

Automated checks (0)

No automated checks map to this article yet.

Buyer due-diligence checklist

  • Run an SSL Labs test (ssllabs.com/ssltest) — minimum grade B.
  • Check for mixed content (HTTP images/scripts on HTTPS pages).
  • Verify HSTS header is set (forces HTTPS for future visits).
  • Ask for evidence of encryption at rest (database, backups).

Run this scan on your site

See exactly where your site stands on Art.32 before a buyer asks.

Scan free →