Get a GDPR pentest
Does your organization process personal data and do you want to demonstrably comply with article 32 GDPR? Does a controller require technical evidence of your security measures? Have you performed a DPIA in which pentesting was identified as a control measure? For these situations a pentest provides concrete, independent validation that your technical and organizational measures actually work.
DongIT delivers GDPR pentests specifically aligned with article 32 GDPR and the eight NOREA privacy principles from article 5 GDPR. Findings are mapped to the relevant GDPR obligations so your Data Protection Officer (DPO), compliance officer or external auditor has standardized evidence directly available.
Our pentests are performed by OSCP-certified ethical hackers under our four-eyes principle: minimum of two testers per engagement with peer review on every finding. Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited. Data stays in Europe, no US-hosting.

What we test in a GDPR pentest
A GDPR pentest assesses your applications, infrastructure and networks against the technical security measures from article 32 GDPR. We explicitly map every finding to the relevant GDPR obligation, so your Data Protection Officer and external auditor have standardized evidence directly available.
- Article 32 GDPR: security of processing. Appropriate technical and organizational measures, encryption, pseudonymization, resilience and recovery capability.
- Article 25 GDPR: privacy by design and by default. Assessment of whether privacy principles are structurally embedded in the architecture of your applications.
- Article 5(1)(c): data minimization. Verification that only necessary personal data is processed and that excessive data collection is absent.
- Article 5(1)(d): data quality. Assessment of integrity of personal data and controls on authorization errors that could lead to incorrect data.
- Article 5(1)(f): integrity and confidentiality. Testing of authorization, access control, transport security and security of data at rest.
- Articles 15 through 22: rights of data subjects. Verification whether technical implementation of access, rectification, erasure and data portability works correctly.
- Articles 33/34: personal data breach detection. Assessment of whether your systems detect personal data breaches in time so you can notify the Dutch Data Protection Authority within 72 hours.
For organizations that need to cover both GDPR and other frameworks (NIS2, ISO 27001, DigiD), we can double-map findings to multiple frameworks in one report. This saves time and cost compared to multiple separate engagements.
Why not to delay your GDPR pentest
The GDPR has applied since 25 May 2018 and the Dutch Data Protection Authority (AP) actively enforces. Personal data breaches and shortcomings in security measures lead to substantial fines and reputational damage. For organizations that process personal data, three situations are especially reason to invest now in demonstrable compliance:
DPIA obligation
For processing operations with high privacy risks, a Data Protection Impact Assessment is mandatory (article 35 GDPR). Pentesting is often an identified control measure that must be demonstrably implemented.
Processor obligations
Processors must implement demonstrably appropriate technical measures per article 28 GDPR. Enterprise clients increasingly require pentest reporting as evidence before signing Data Processing Agreements.
Breach prevention
Notification obligation for personal data breaches applies within 72 hours to the AP and, in case of high risk, to data subjects. A pentest identifies vulnerabilities before attackers exploit them and before you have to activate the notification obligation.
What if you are not compliant? GDPR provides for fines up to €20 million or 4% of global annual turnover (category 2 violations) and up to €10 million or 2% of global turnover (category 1). Recent enforcement in the Netherlands actively focuses on inadequate technical measures, including insufficient authentication and deficient logging.
Why choose DongIT for your GDPR pentest
GDPR compliance requires a pentest partner who understands what the law demands both technically and legally. We combine OSCP-certified ethical hackers with in-depth knowledge of privacy legislation and NOREA frameworks for privacy audits.
- Data stays in Europe. Our Security Reporter platform runs on European infrastructure, no US-hosting. Under Schrems II and GDPR a concrete advantage for your international data transfers.
- CCV Keurmerk Pentesten. Independent accreditation that safeguards the quality and methodology of our pentests. For your DPO and internal audit an additional quality indicator.
- ISO 27001:2022 certified. DongIT is itself certified for information security. We know first-hand what auditors expect.
- Four-eyes principle. Minimum of two OSCP-certified pentesters per engagement with peer review on every finding. Additional quality assurance for your GDPR reporting.
- 500+ organizations have relied on our pentests since 2012, in sectors with high privacy sensitivity: healthcare, financial, government and HR technology.
- NOREA-compliant reporting. Findings structured per NOREA privacy principles, directly usable for your privacy audit.
Our approach: from pentest to GDPR reporting
We follow a structured approach aligned with how GDPR supervision and internal privacy audits work. Every step delivers evidence you can use for your Data Protection Officer, controllers and external auditor.
Scope alignment with your processing operations
We jointly determine which applications and systems process personal data and which components have priority. This aligns with your record of processing activities (article 30) and any DPIA outcomes.
Technical pentest
Manual testing by OSCP-certified ethical hackers under our four-eyes principle, supplemented with automated tooling. Testing per NCSC guidelines, OWASP and NOREA frameworks.
Reporting with GDPR mapping
Delivery via Security Reporter. Every finding mapped to the relevant GDPR obligation (article 32, article 25 and article 5 principles), with CVSS scoring and remediation guidance. Directly usable for your GDPR reporting and internal privacy audit.
Remediation support
Our specialists support your team with interpreting findings and prioritizing remediation. Critical privacy risks are prioritized so breach prevention is in order.
Retest and audit support
Formal retest of resolved vulnerabilities. During external privacy audits we can be present to answer technical questions from your auditor or AP inspector directly.
Who benefits from a GDPR pentest?
GDPR applies to every organization that processes personal data of EU citizens, regardless of sector or size. For certain categories of processing operations a pentest is particularly relevant:
High-risk processing
Organizations for which a DPIA is mandatory:
- Large-scale processing of special categories of personal data (medical, biometric)
- Systematic monitoring of individuals
- Automated decision-making with legal consequences
- Large-scale geographic location tracking
- Combination of different data sources
Standard GDPR obligation
Every organization that processes personal data and must account for:
- Data Processing Agreements with enterprise clients
- Internal or external privacy audits
- Breach prevention and notification preparation
- Accountability toward the Dutch Data Protection Authority
- ISO 27001, NIS2 or DigiD audits with privacy scope
For SaaS vendors and processors delivering to enterprise clients, demonstrable GDPR compliance is often a condition for contract signing. Our reporting can be shared directly with your clients or their compliance teams.
Combining with other compliance engagements
GDPR overlaps substantially with other compliance frameworks. We can structure your pentest engagement more efficiently by covering multiple frameworks in parallel:
GDPR and ISO 27001
ISO 27001 Annex A.5.34 specifically addresses privacy and protection of personal data. Findings double-mapped to GDPR and ISO 27001:2022 controls.
GDPR and NIS2
For essential and important entities. GDPR and the Dutch Cybersecurity Act overlap on security measures; we structure reporting to both frameworks.
GDPR and DigiD
For government organizations with a DigiD connection. Citizen personal data requires double protection under both GDPR and the DigiD normenkader.
GDPR and NEN 7510
For healthcare organizations and healthcare IT vendors. NEN 7510 requires information security in healthcare; GDPR special categories of personal data require additional measures.
GDPR and DORA
For financial entities. DORA obligations combined with GDPR for customer personal data. One coordinated engagement.
GDPR and cyber insurance
An increasing number of cyber insurers require demonstrable GDPR compliance as a condition for coverage, especially after personal data breach incidents. Our reporting meets these requirements.
What does a GDPR pentest cost?
The price depends on the size of your processing operations, the number of systems and applications and any combined scopes with other compliance frameworks. For clearly defined engagements we offer standard packages. For more complex engagements with multiple applications or large-scale processing operations we work with a scoping conversation and a tailored quotation.
- Quick Pentest, €2,960 excl. VAT
- Expert Pentest, from €5,040 excl. VAT (most chosen)
- Extensive Pentest, from €7,200 excl. VAT
- Enterprise and multi-scope engagements, tailored quotation
Record of processing as starting point
For every GDPR engagement we start with a complimentary scoping conversation covering your record of processing activities, DPIA outcomes and compliance priorities. This ensures you know exactly what the investment will be.
Frequently asked questions about GDPR pentesting
Below are the most frequently asked questions about GDPR pentesting. For a complete overview please visit our FAQ page.
Is a pentest legally required under GDPR?
Article 32 GDPR requires "appropriate technical and organizational measures" and explicitly "a process for regularly testing, assessing and evaluating the effectiveness" of security measures. A pentest is one of the most concrete implementations of this. For processing operations with high privacy risks (DPIA-mandatory per article 35), pentesting is often specifically identified as a control measure.
What are the fines for GDPR shortcomings?
Category 1 violations (procedural shortcomings such as missing record of processing activities) can result in fines up to €10 million or 2% of global annual turnover. Category 2 violations (breach of data subject rights or inadequate security) can lead to €20 million or 4% of global turnover. The higher of the two amounts applies.
How often should I have a GDPR pentest performed?
GDPR does not prescribe a specific frequency, but article 32 requires "regularly" testing. Market standard is annually, with additional tests after significant changes to applications, processing operations or threat landscape. For SaaS vendors, biannual pentesting is often common.
Does my data stay in Europe during the pentest?
Yes. Our Security Reporter reporting platform runs on European infrastructure, no US-hosting. Test data and findings are processed within the Netherlands. For you as controller, this means the pentest does not introduce additional international data transfer questions (Schrems II).
Do you work with Data Protection Officers?
Yes. Our reporting is deliberately structured so your DPO can immediately see which findings affect which GDPR articles. We can have brief contact with your DPO during the pentest phase to align on scope questions, and after completion present our findings during your internal privacy review.
What if a personal data breach is found during the pentest?
If we detect an active personal data breach during the pentest, we report this to you immediately with an interim report. You can then assess whether the notification obligation to the AP is triggered. Our findings themselves are not a personal data breach under GDPR, unless personal data has actually left your organization.
Can you support with a DPIA?
Our pentest provides the technical evidence for the "security" component of your DPIA. We are not a legal advisor, but we work with privacy consultants and law firms that guide the procedural DPIA engagement. On request we can refer you.
Does a GDPR pentest combine well with NIS2 or ISO 27001?
Yes. GDPR, NIS2 (Dutch Cybersecurity Act) and ISO 27001 overlap substantially on security measures. We can double-map findings to multiple frameworks in one report. This saves time and cost compared to multiple separate engagements.
How long does a GDPR pentest take?
Active testing time ranges from 24 hours for a compact scope to 80 hours or more for extensive multi-application engagements. Total duration from scoping conversation to final report and retest is typically 4 to 8 weeks.
Ready for your GDPR reporting?
Working toward demonstrable GDPR compliance? Preparing for a privacy audit? Does an enterprise client require a GDPR statement in your Data Processing Agreement? We start with a complimentary scoping conversation covering your record of processing activities and compliance strategy. Response within one business day. Quotation within three business days.
Nederlands