Datawiza
Back to blog
Published July 20, 2026Blog

Does GDPR Require MFA? No — and Here Is the Part That Still Costs Companies Millions

GDPR MFA abstract feature image
Table of contents

No. GDPR does not require multi-factor authentication by name.

That honest answer matters because many pages blur the distinction. GDPR Article 32 requires appropriate technical and organizational measures to ensure a level of security appropriate to the risk. It is deliberately technology-neutral. It does not say "you must deploy MFA."

But that does not mean password-only access is safe. When a credential-driven breach happens, the regulator asks whether the security measures were appropriate for the data, risk, state of the art, and system environment. Missing MFA can become evidence that they were not.

What Article 32 Actually Says

Article 32 requires appropriate security measures considering the state of the art, implementation cost, processing context, and risk to individuals. It lists examples such as pseudonymization, encryption, resilience, restoration, and regular testing.

MFA is not listed. The legal test is broader: did the organization implement security appropriate to the risk?

Why MFA Still Shows Up in Enforcement

The ICO's March 2025 Advanced Computer Software Group penalty is the clearest coverage-gap example. Hackers accessed systems through a customer account that did not have MFA. The ICO fined Advanced GBP 3.07 million after a ransomware incident affecting health and care systems.

The ICO's 23andMe action is another example. The ICO fined 23andMe GBP 2.31 million after credential stuffing exposed UK users' sensitive genetic data. The ICO summarized failures including lack of appropriate authentication and verification measures, such as mandatory MFA.

The lesson is not "GDPR mandates MFA." The lesson is that after a breach, weak authentication on a high-risk system is difficult to defend as appropriate security.

Coverage Matters More Than Policy

The Advanced case is especially useful for security teams because the issue was coverage. The attacker did not need to defeat the strongest part of the estate. The attacker used an account without MFA.

That is the same pattern many organizations face:

  • The corporate IdP has MFA.
  • The main SaaS estate has MFA.
  • The high-risk legacy application does not.
  • The user account that gets attacked sits in the gap.

What Systems Should Be Prioritized

For GDPR risk, prioritize systems that process significant personal data:

  • HR systems.
  • Customer portals.
  • CRM and support consoles.
  • Healthcare, finance, or identity data applications.
  • Legacy applications with local login.
  • Admin paths that can export or modify personal data.

How Datawiza Helps

Datawiza Access Proxy enforces MFA at the access layer before users reach protected web applications. The application does not need to support modern SSO or MFA natively.

Use an existing IdP when appropriate, or use Datawiza built-in MFA when the user population is outside your IdP. That helps close the coverage gap that regulators care about most: the sensitive application no one could modify in time.

Sources Reviewed

FAQ

Does GDPR require MFA?

No. GDPR does not mandate MFA by name. Article 32 requires security appropriate to the risk.

Can a company be fined under GDPR for not having MFA?

Not simply because a specific MFA clause was violated. But after a credential-driven breach, regulators can treat missing MFA as evidence that the organization's security measures were not appropriate to the risk.

Which systems are highest risk under GDPR?

Systems that process significant personal data, especially HR, CRM, customer portals, health data systems, support consoles, and admin tools.

Is MFA enough for GDPR Article 32?

No. MFA is one control. Article 32 also expects broader measures such as access control, resilience, testing, encryption where appropriate, monitoring, and incident response.

Datawiza is Easy to Get Started

Sign up to secure your AI agents and critical enterprise apps

Try Datawiza