Skip to content
PeekWellThe Rulebook
Join now

GDPR Article 32: HTTPS and security headers

At a glance

EU-15LowGDPR Art. 32; Art. 83(4)

Peeky reads what your server tells every visitor's browser: whether the connection is encrypted, whether the site's TLS identity is in date, and whether the usual browser protections are switched on.

Last checked against the source:

I need to fix thisI need the rule

The rule

Article 32 of the GDPR is headed security of processing. It is short, it is risk-based, and it names no technology. The wording below is taken from the Official Journal text, read at the Publications Office mirror.

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (a) the pseudonymisation and encryption of personal data.

The measures are proportionate to the risk, so a login form that carries invoices is held to more than a brochure page, and “state of the art” moves over time.

The article does not mention HSTS, content security headers or TLS versions. Those come from regulators’ guidance. The CNIL’s web security page, dated 14 March 2024, asks organisations to “mettre en œuvre le protocole TLS sur tous les sites web, en utilisant uniquement les versions les plus récentes”, and to make it mandatory on pages that handle authentication or personal data. The CNIL’s 2020 sheet on securing websites asks for TLS 1.2 or 1.3, TLS on all pages, and mentions HSTS to force HTTPS for authentication cookies. Neither page names Content-Security-Policy or X-Frame-Options, so those two headers are better described as widely used practice than as something an authority has asked for.

Penalties sit in two tiers. The CNIL’s own page gives the general ceiling as 10 million euros or 2% of worldwide annual turnover, and 20 million euros or 4% for the most serious infringements. Article 83(4)(a) places the controller’s and processor’s obligations under Articles 25 to 39, which include Article 32, in the lower tier; the same numbering appears in the retained UK text. The check’s citation lists Art. 83(4), and that is where this obligation sits. Authorities often cite Article 32 together with Article 5(1)(f), which sits in the upper tier.

What PeekWell checks and how

EU-15 asks what your server says about itself to every visitor. It does not ask whether the site can be broken into, and it cannot answer that.

The scan opens a public page the way an ordinary browser does. It reads the TLS handshake, which gives the protocol version, the cipher and whether the site’s TLS identity is in date, and it reads the response headers. It looks at HSTS, Content-Security-Policy and X-Frame-Options, and it notes mixed content, which is a page loaded over HTTPS that still pulls in some resources over plain http. The results are compared with a baseline. An expired or weak certificate, a missing HSTS header, a missing Content-Security-Policy header or mixed content becomes a finding. HSTS, Content-Security-Policy and X-Frame-Options are all read.

The decision is made by code from what the server sent. A language model may help word the explanation, but it never decides that a header is absent. The default severity is low, and the report frames a gap as a question about appropriate measures, never as a proven failure.

The scan has limits, and the report says so. It reads the advertised TLS and header setup of the public pages it visited, and nothing more. It does not sign in, submit forms, test passwords, send unusual requests or open addresses nobody linked to. It cannot see how data is stored, who has access inside the company, or what happens on a server after a form is sent. A Passed means the expected setup was observed on the pages scanned. It does not say the site complies.

The same engine runs for the British and American rules. UK-15 and US-15 describe the same observation read against their own law. US-15 adds a check of well-known paths, which this check does not do.

Why it matters for a company

None of the decisions below is about a missing header. The Garante and the CNIL have dealt with the layer underneath: whether data travels in the clear, and whether documents are reachable by anyone who asks.

In October 2022 the Garante decided a complaint about a water utility. Users signed in to a customer area, where they saw names, tax codes, contact details and invoices for about 13,000 registered users, including over 2,000 businesses. The area ran over http. The Garante wrote that failing to use cryptographic techniques for the transport of data amounts to an infringement of Articles 5(1)(f) and 32, and that the company should have adopted a secure protocol “quale il protocollo https” from the design stage. It set the fine at 15,000 euros, counting the number of users and the fact that the company had not acted after the complainant raised the problem twice.

The CNIL’s SERGIC decision of 28 May 2019 concerned documents sent by rental applicants. Changing the number in an address returned someone else’s file, with no authentication step. The CNIL called an authentication procedure “une précaution d’usage essentielle”, noted that the flaw was known from March 2018, and recorded the company’s statement that a fix was due to go into production on 17 September 2018. It fined the company 400,000 euros for this flaw and for keeping applicants’ data longer than needed (Articles 32 and 5(1)(e)).

On transport itself the CNIL has written to organisations. Its 2023 report records 39 formal notices to public bodies, such as regions and municipalities, whose sites did not use HTTPS. Its March 2024 note on simplified sanctions describes fines for organisations that kept TLS 1.0 or 1.1, and the SHA-1 hash function, after a formal notice. The page does not name them.

For a company the practical points are three. These facts are visible from outside, so an authority needs no inside access to notice them. In several of the matters above, a complaint or a formal notice came first. And the cost of leaving a known gap open grows with the number of people whose data passes through it.

Smaller companies and larger companies

Article 32 has no size threshold, but it is risk-based, so the same gap weighs differently depending on what the site carries. The risk is about the data and the people, not the headcount.

In a small company the site usually sits on a hosted builder or a managed plan, which switches on HTTPS for the main address. The gaps appear at the edges. An old shop subdomain still answers on http. Product images are linked with absolute http addresses from years ago, so every page has mixed content. A TLS identity expires because the renewal was tied to one person’s card or inbox. Headers are not set because nobody owns the server configuration, and the host’s default does not include them. No decision against a company confirmed as small was found for this check.

In a larger company the same problems multiply. There are dozens of hostnames, campaign microsites built by agencies, legacy portals, and tag managers that inject third-party scripts. A content security header is often loosened or dropped because it broke a tag, and then never tightened. TLS settings differ between the main site and the customer area, which is the pattern in the SERGIC and water-utility decisions: the public front looks fine and the sign-in or document area behind it does not.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • SERGIC

    CNIL (France), 2019€400,000

    The CNIL found that applicants' documents could be read by anyone who changed the number in a web address, with no sign-in required, across 290,870 files in one directory. It treated the missing authentication step as an essential precaution under Article 32. The company had known of the flaw from March 2018, and the company said a fix was due to go into production on 17 September 2018. The company had 486 employees and a turnover of 43 million euros in 2017.

    Read the CNIL (France) publication about SERGIC
  • Servizio Idrico Integrato S.c.p.a.

    Garante (Italy), 2022€15,000

    After a complaint, the Garante found that the company's customer area, where users signed in and saw names, tax codes, contact details and invoices for about 13,000 registered users, ran over unencrypted http. It found infringements of Articles 5(1)(f), 25(1) and 32, and recorded that the complainant had raised the problem with the company twice and that the company had not acted before the Garante opened its inquiry.

    Read the Garante (Italy) publication about Servizio Idrico Integrato S.c.p.a.

Smaller companies

No decision against a company shown to be small, at the authority's own page, was found for this check. The Garante decision gives no headcount or turnover for the water utility, which serves over 220,000 residents; it is shown as large on that basis, not on a stated size.

How to fix it

The order below follows what the CNIL’s guidance asks for: TLS on all pages, only recent versions, and HSTS to force the encrypted version.

  1. List every hostname. Write down the main domain, www, the shop, the customer area, the blog and any subdomain your site links to. Check each one in a private window. Include the ones an agency built.
  2. Redirect http to https everywhere. Use a permanent redirect on every hostname and make sure the redirect goes to the same host, not through a third-party address.
  3. Allow only TLS 1.2 and 1.3. Switch off older versions and weak ciphers in the server, load balancer or CDN settings. The CNIL’s guidance asks for recent versions only.
  4. Automate renewal and watch the dates. Set the TLS identity to renew by itself and send expiry warnings to a shared mailbox, not a person.
  5. Fix mixed content. Search templates, the database and the page builder for http:// links to images, scripts and fonts. Change them to https:// or to relative paths.
  6. Add HSTS, then raise it. Start with a short max-age, check nothing breaks, then extend it. Add includeSubDomains only once every subdomain answers over HTTPS.
  7. Add the content security headers. Start Content-Security-Policy in report-only mode and read the reports. Set frame-ancestors or X-Frame-Options so other sites cannot frame yours.
  8. Re-scan. Run a scan again and check that the TLS and header findings are gone.
add_header Strict-Transport-Security "max-age=86400" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Content-Security-Policy-Report-Only "default-src 'self'" always;

The snippet is a starting point, not a finished policy. A real content security policy has to list the scripts and services your pages use, and your adviser can say what suits your risk. Peeky reports only what it sees.

Questions

What does GDPR Article 32 require for a website?

Appropriate technical and organisational measures, matched to the risk. The article does not list headers or protocol versions. It asks the company to weigh the state of the art, the cost and the harm that could follow, and regulators fill in the detail through guidance and decisions.

For a website, that guidance is mostly about encrypting the connection. The rule shows the wording.

Does GDPR require encryption?

It names encryption as one example of an appropriate measure, not as a flat requirement. Article 32(1) lists, among measures to be taken "as appropriate", "the pseudonymisation and encryption of personal data". In its 2022 decision on a water utility, the Garante treated a sign-in area with no encryption in transit as an infringement.

Are security headers required by GDPR?

No authority page read for this article names them as a requirement. The CNIL's web security guidance names TLS, and its 2020 sheet mentions HSTS. Headers such as Content-Security-Policy are common practice, and Peeky reports them as context under Article 32, not as a rule on their own.

What is HSTS and why do regulators mention it?

HSTS is a header that tells a browser to use the encrypted version of your site every time. The CNIL's 2020 guidance on securing websites mentions it as a way to force HTTPS for authentication cookies. A scan can read it from your server's reply.

Is http instead of https a GDPR problem?

It can be, when the page carries personal data. The Garante fined a company 15,000 euros because users signed in and handled their data over http. A page with nothing personal on it is a different question, and the Garante's reasoning was about data sent between the visitor and the server.

Filed with

The rule

GDPR (Regulation (EU) 2016/679), Arts. 5(1)(f), 32 and 83(4)

Read the rule (GDPR (Regulation (EU) 2016/679), Arts. 5(1)(f), 32 and 83(4))

A case

SERGIC

CNIL (France), 2019

Read the decision (SERGIC)

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. Garante per la protezione dei dati personali, Ordinanza ingiunzione nei confronti di Servizio Idrico Integrato S.c.p.a., 6 October 2022 [doc. web 9817058]
  2. Garante, Newsletter of 24 October 2022 on secure protocols for online services [doc. web 9817079]
  3. CNIL, Deliberation SAN-2019-005 of 28 May 2019 (SERGIC), on Legifrance
  4. CNIL, Sécuriser les sites web, page dated 14 March 2024
  5. CNIL, Sheet no. 6: Secure your websites, applications and servers, 11 June 2020
  6. CNIL, Sanctions et mesures correctrices : le bilan 2023, page dated 16 February 2024 (39 formal notices on HTTPS)
  7. CNIL, Fifteen new sanctions under the simplified procedure since January 2024, 12 March 2024
  8. CNIL, Sécurité des sites web : les 5 problèmes les plus souvent constatés, 27 June 2018
  9. CNIL, Quelles sanctions peuvent être prononcées par la CNIL
  10. legislation.gov.uk, UK GDPR Art. 83 (retained text, same numbering as the EU original)

Last checked against the source:

For information only. Not legal advice.