UK GDPR Article 32 asks for appropriate technical and organisational measures, taking into account the state of the art, cost, nature of processing, and risk to people. It does not name VAPT. That is not a free pass to skip testing.
When it is appropriate
You process special category data, payment data, or large volumes of customer records in a multi-user application. You have had a near-miss. A customer with bargaining power has asked. You are going through ISO 27001 and the auditor asked how you validate access control. Those are pentest-shaped problems.
What the ICO actually reads after an incident
Whether you knew the class of issue existed. Whether you had tested it. Whether you had fixed a previous finding and verified the fix. A scanner PDF dated 14 months ago does not help. A re-tested, scoped report from this quarter might.
Data minimisation during the test
We take bounded proof — a few rows, a screenshot, a replay — not your production warehouse. That is both professional ethics and UK GDPR. The authorisation letter names this.
Processors and sub-processors
If you are a UK processor, your controller may contractually require independent testing. Send them the letter of attestation and the executive summary, not the exploit steps, unless they are entitled to the full report.
Need this as an engagement, not an article?
UK hours. GBP quote. Written CMA 1990 authorisation.
Request a pentest