GDPR
General Data Protection Regulation · Regulation (EU) 2016/679
Article 32(1) — Security of processing
“the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk… the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.”
Note. EUR-Lex is the canonical EU regulator source but does not serve per-article fragment anchors. The UK post-Brexit retained version on legislation.gov.uk is substantively identical for this article and provides a scrollable deep link.
Why it cannot be verified
"Appropriate" and "appropriate to the risk" are self-graded standards defined by the controller. A data subject has no way to observe "unauthorised processing" from outside the controller’s systems, and Article 30 records are shared only with supervisory authorities on request — never with the affected person.
What structure changes
The per-user Merkle chain is not a policy attestation. It is a cryptographic record of every access, verifiable by the data subject in their own browser. "Appropriate" stops being a word and becomes a hash.
Enforcement on record. Meta Platforms Ireland Limited, May 2023: €1.2B fine under GDPR Article 46 for international data transfers. Amazon Europe, July 2021: €746M fine. The underlying audit evidence both companies produced was a standard query against their own internal logs.