Technical and organisational measures (TOMs)

Data protection glossary · 1 minute read

Technical and organisational measures are the specific precautions a company takes to protect personal data.

What they include

They include, for example, encryption, access concepts, backups and training. The GDPR requires measures that are appropriate to the risk of the processing, and requires them to be documented.

Art. 32 GDPR cites as examples pseudonymisation and encryption, ensuring confidentiality, integrity, availability and resilience, the ability to restore data promptly after an incident and a process for regularly testing effectiveness.

Structuring in practice

Many companies still structure their TOMs according to the control objectives of the former BDSG, such as physical access, system access, data access, transfer, input and availability control. The description of the TOMs forms part of the record of processing activities and is regularly an annex to the data processing agreement.

Art. 32 GDPR
Security of processing.
Arts. 24 and 25 GDPR
Responsibility and data protection by design.
Art. 30(1)(g) GDPR
Description of the TOMs in the record of processing activities.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.