EU data protection authorities want to see you tested your controls, not just documented them.
GDPR doesn't name "penetration test" as a required control, but Article 32 requires a process for regularly testing the effectiveness of technical security measures — and a documented pentest report is the most direct evidence most data controllers and processors can produce. This page is for the privacy or security lead who needs that evidence on file, on a reasonable timeline, without three weeks of vendor calls first.