---
title: "GDPR: What measures for mobile security?"
description: GDPR applies to any company holding personal data of european citizens and involves big changes of the mobile security landscape around the world.
image: https://blog.pradeo.com/hubfs/gdpr-data-protection-regulation.jpg
---

[![pradeo\_logo\_color](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_color.png?width=220&height=33&name=pradeo_logo_color.png "pradeo_logo_color")](https://pradeo.com)

- Solutions 
    - [Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Secure Private Store](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
    - [Mobile Application Compliance Audit](https://pradeo.com/en/solutions/mobile-application-security/application-compliance-audit/)
    - [Runtime Application Self Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/)
    - [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)
    - [Application Security Testing](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
- Use cases 
    - [Cybersecurity in MDM/ UEM](https://pradeo.com/en/use-cases/cybersecurity-in-mdm-uem/)
    - [Securing mobile devices](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Securing Mobile Applications](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
    - [Malware / leakware protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Phishing protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Ensuring compliance for applications](https://pradeo.com/en/compliance/)
    - [Ensuring compliance for mobile fleet](https://pradeo.com/en/compliance/)
    - [Securing BYOD](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
- [Become partner](https://pradeo.com/become-partner/)
- Resources 
    - [Solution briefs](https://pradeo.com/en/resources/?solution-briefs)
    - [Customer Cases](https://pradeo.com/en/resources/?customer-cases)
    - [Integration briefs](https://pradeo.com/en/resources/?integration-briefs)
    - [White Papers](https://pradeo.com/en/resources/?white-papers)
    - [Analyst reports & guides](https://pradeo.com/en/resources/?analyst-reports-guides)
    - [On demand webcast](https://pradeo.com/en/resources/?webcasts-on-demand)
    - [About us](https://pradeo.com/en/about/)
- [Blog](https://blog.pradeo.com/)
- [Contact](https://pradeo.com/contact/)
- en 
    - [**FR**](https://blog.pradeo.com/fr)
    - [**DE**](https://blog.pradeo.com/de)

### Topics

- Select a Topic

### Stay up to date

 SUBSCRIBE TO OUR BLOG

### Stay up to date

[Mobile Security](https://blog.pradeo.com/topic/mobile-security)

# GDPR: What measures for mobile security?

![Picture of Roxane Suau](https://blog.pradeo.com/hubfs/roxane-suau.jpg)

 By [Roxane Suau](https://blog.pradeo.com/author/roxane-suau) on April, 20 2017

[mailto:?subject=Take%20a%20look%20at%20this%20article](mailto:?subject=Take%20a%20look%20at%20this%20article)

![](https://blog.pradeo.com/hubfs/gdpr-data-protection-regulation.jpg)

In May 2018, a European privacy law is due to take effect that will require big changes, and potentially significant investments, by organizations worldwide. The **General Data Protection Regulation (GDPR)** is an initiative by which the European Union intends to give citizens regain control over personal data, and privacy.

The purpose is also to harmonize the current data protection laws across the EU member states. It is a “regulation” rather than a “directive” meaning it will be law directly applicable to all EU member states, essentially taking precedence over existing national regulations.

Under GDPR organizations that store, archive and otherwise handle personal data will be held accountable to same confidentiality, privacy and security across the EU. This applies to all organizations and entities public or private, regardless of jurisdiction, that handle data pertaining to EU citizens and residents.

Compliance under GDPR is strict and sanctions that could result in case of non-compliance or data breaches are severe. However, according to a DMA (Direct Marketing Association) survey, 68% of companies think today that they won’t be compliant in time.

With the generalization and ever expanding use of mobile applications and governments changing data privacy rules and regulations, the security box will no longer be an option for mobile applications but a necessity.

GDPR articles 25, 32, 33, 34 and 35 focus on practicable elements for application security as they emphasize testing, preventing and handling data breaches.

## CURRENT STATE

The new regulation stipulates that one of the first compliance steps consists of an audit. This is to determine how a company currently protects and handles private data, and is compliant with GDPR. If an audit reveals it’s not the case, a curative plan is required.

**Recommendation #1:** Executing [security diagnostics at the application level](https://www.pradeo.com/en-US/apps-security-testing) will reveal vulnerabilities and hidden behaviors, and validate or invalidate compliance.

 

## DATA PROTECTION FROM THE CONCEPTION

This is one of the most important aspects of GDPR. On the one hand, it is expected companies will include data privacy protection as part of their development process. On the other hand, they must apply the appropriate technical means and methods and organizational processes to ensure only relevant data collection, processing and storage.

**Recommendation #2:** In an application development context, this means building security and confidentiality as core to the initial development steps. To do so, developers can resort to a security testing API that is integrated in their work platforms to [audit application security levels](https://blog.pradeo.com/mobile-application-security-testing-a-must-do) during the whole development process.

 

## SECURITY ADAPTED TO RISKS

GDPR asks companies to guarantee users security that is commensurate to risk levels. Organizations must put in place procedures to regularly test, analyze and evaluate security practices, to fully ensure processes for data confidentiality and integrity.

**Recommendation #3:** This security level can include personal data encryption, pseudonymizing or a [self-protection SDK](https://www.pradeo.com/en-US/in-app-protection) integrated in applications’ source codes. This must protect them against threats on devices where other applications co-reside or may be installed and established or impending network connections.

## IN CASE OF DATA BREACH

When a breach is detected, the company must notify the competent regulator within 72 hours. If the breach carries a high risk for some users, the company must also warn them.

It is also asked to companies to retain internal reports of all data breach incidents that could compromise data privacy, as well as remediation steps taken and resulting outcomes.

Data breaches can lead to a fine of up to 20 million of euros, or 4% of the company’s global annual revenue (whichever is the highest amount). For example, Tesco Bank would have been liable for 2.2 billion euros fine following a breach at the end of 2016, if the new regulation had already been enforced.

**Recommendation #4: **Companies have to use monitoring tools to track their web and mobile activities – which are the main sources of attacks. Setting up and updating SOC (Security Operating Center) or SIEM (Security Information and Event Management) platforms will provide analysis and investigation materials in case of a data leakage. It’s also advised to anticipate data breach notification procedures to be more reactive if the time comes.

 

## THE COST OF NON-COMPLIANCE

Every companies whose practices are not GDPR compliant starting in May 2018 risk up to a fine of 10 million of euros or 2% of the company’s global annual revenue (whichever is the highest amount).

On top of the penalty, non-compliant companies will need to confront customers and prospective customer’s reactions with regards to data breaches/theft and assume reputational risk for their brand.

**Recommendation #5:** GDPR asks for transparency, aligning now will allow to improve current security measures and will ensure a total compliance readiness on time.

 

 

To conclude, GDPR requirements are more security guidelines to protect European citizens and their information assets. They are not entirely new or problematic for Pradeo, as data protection is our core activity since day one. Our technology and our tools are compliant with the new regulation and are available today to help your company smoothly transition to GDPR compliance.

 

###### About The Author

[More from this author](https://blog.pradeo.com/author/roxane-suau)

![](https://blog.pradeo.com/hs-fs/hubfs/roxane-suau.jpg?height=100&name=roxane-suau.jpg)

###### Roxane Suau

#### Recommended articles

[![Smartphones: massive data leaks… that are perfectly legal](https://blog.pradeo.com/hubfs/Template%20article%20(14)-1.png)](https://blog.pradeo.com/smartphones-massive-data-leaks-that-are-perfectly-legal)

###### [Smartphones: massive data leaks… that are perfectly legal](https://blog.pradeo.com/smartphones-massive-data-leaks-that-are-perfectly-legal)

 \- December 18, 2025

[![Mobile threats: what the new ANSSI report reveals](https://blog.pradeo.com/hubfs/Template%20article%20(11)-1.png)](https://blog.pradeo.com/mobile-threats-what-the-new-anssi-report-reveals)

###### [Mobile threats: what the new ANSSI report reveals](https://blog.pradeo.com/mobile-threats-what-the-new-anssi-report-reveals)

 \- December 4, 2025

[![Techstep chooses Pradeo to provide next-level Mobile Threat Defense to its users](https://blog.pradeo.com/hubfs/Template%20article%20(13).png)](https://blog.pradeo.com/techstep-chooses-pradeo-to-provide-next-level-mobile-threat-defense-to-its-users)

###### [Techstep chooses Pradeo to provide next-level Mobile Threat Defense to its users](https://blog.pradeo.com/techstep-chooses-pradeo-to-provide-next-level-mobile-threat-defense-to-its-users)

 \- November 20, 2025

### Popular articles

### Stay up to date

### Recent articles

### Articles récents

[Fence integrates Pradeo's technology to secure its clients' mobile fleets](https://blog.pradeo.com/fence-integrates-pradeos-technology-to-secure-its-clients-mobile-fleets-1)

 \- 20 April, 2017

[RedHook: the banking trojan that grants itself system-level access on Android](https://blog.pradeo.com/redhook-the-banking-trojan-that-grants-itself-system-level-access-on-android)

 \- 20 April, 2017

[What Google's latest report reveals about mobile threats](https://blog.pradeo.com/what-googles-latest-report-reveals-about-mobile-threats)

 \- 20 April, 2017

[Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- 20 April, 2017

[Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 \- 20 April, 2017

### Topics

- [Mobile Security (56)](https://blog.pradeo.com/topic/mobile-security)
- [Mobile Application Security (46)](https://blog.pradeo.com/topic/mobile-application-security)
- [Expertise (31)](https://blog.pradeo.com/topic/expertise)
- [Security Alert (30)](https://blog.pradeo.com/topic/security-alert)
- [Cybersecurity (29)](https://blog.pradeo.com/topic/cybersecurity)
- [News (28)](https://blog.pradeo.com/topic/news)
- [Partners (25)](https://blog.pradeo.com/topic/partners)
- [Corporate (12)](https://blog.pradeo.com/topic/corporate)
- [Events (4)](https://blog.pradeo.com/topic/events)
- [Actualité (2)](https://blog.pradeo.com/topic/actualité)
- [predictions (2)](https://blog.pradeo.com/topic/predictions)
- [cyberattack (1)](https://blog.pradeo.com/topic/cyberattack)

see all

[![New Call-to-action](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f)

### Get in touch with mobile security experts

[Contact us](https://www.pradeo.com/en-US/contact-us)

[![](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_white_square.png?width=90&height=74&name=pradeo_logo_white_square.png)](https://pradeo.com)

European leader in mobile security, Pradeo protects business mobile devices and applications.

[Read More](https://www.pradeo.com/en-US/)

- [Resources](https://www.pradeo.com/en-US/pradeo-ressources#white_papers)
- [UEM security](https://www.pradeo.com/en-US/uem-mdm-security)
- [Use cases](https://www.pradeo.com/en-US/pradeo-ressources#use-case)
- [Data protection](https://www.pradeo.com/en-US/mobile-data-privacy-regulation)
- [Contact us](https://www.pradeo.com/en-US/contact-us)

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-defense)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence#perso-threat-intelligence)

![email.svg](https://cdn2.hubspot.net/hubfs/3067823/awwal/email.svg "email.svg")

[contact@pradeo.com](mailto:contact@pradeo.com)

Copyright @ 2022. All Right Reserved.

- <https://www.linkedin.com/company/pradeo-security-systems>
- <https://twitter.com/pradeo>
- <https://www.youtube.com/channel/UCD7hgYE8WuipxJtxsHDUdMA>

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Roxane Suau"
  },
  "dateModified" : "January 27, 2021, 11:26:04 AM",
  "datePublished" : "2017-04-20 15:30:42",
  "description" : "GDPR applies to any company holding personal data of european citizens and involves big changes of the mobile security landscape around the world.",
  "headline" : "GDPR: What measures for mobile security?",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://cdn2.hubspot.net/hubfs/2378615/gdpr-data-protection-regulation.jpg"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Logo%20Pradeo%20D%C3%A9grad%C3%A9%20Long%20Couleurs.svg"
    },
    "name" : "Pradeo"
  }
}
```