Privacy
Glossary

Technical and organisational measures

Technical and organisational measures are safeguards used to protect personal data in proportion to risk and to review whether those safeguards remain effective.

In brief

Technical and organisational measures, often called TOMs, protect personal data against unauthorised access, loss, alteration and other unlawful processing. Article 32 GDPR requires a level of security appropriate to the risk. This duty is connected with the controller’s responsibility under Article 24 GDPR and with data protection by design and by default under Article 25 GDPR.

The appropriate measures depend on the processing, the data involved and the possible consequences. Article 32 GDPR refers, among other things, to pseudonymisation and encryption, the ability to ensure confidentiality, integrity, availability and resilience, procedures for restoring availability and access, and regular testing and evaluation of effectiveness. The subject is therefore not limited to IT settings. It also includes permissions, responsibilities, staff training, incident procedures and oversight of service providers.

A general security checklist is not enough for a business. Measures should match the actual processing activities, be documented in a way that can be followed and be reviewed when processing or risks change. The processors and service providers topic explains the contractual context. The processor agreement check and the processor checklist help organise the first set of evidence. The page on privacy compliance and governance provides further orientation on responsibilities and ongoing controls.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich