Technical and organisational measures are the specific precautions a company takes to protect personal data.
What they include
They include, for example, encryption, access concepts, backups and training. The GDPR requires measures that are appropriate to the risk of the processing, and requires them to be documented.
Art. 32 GDPR cites as examples pseudonymisation and encryption, ensuring confidentiality, integrity, availability and resilience, the ability to restore data promptly after an incident and a process for regularly testing effectiveness.
Structuring in practice
Many companies still structure their TOMs according to the control objectives of the former BDSG, such as physical access, system access, data access, transfer, input and availability control. The description of the TOMs forms part of the record of processing activities and is regularly an annex to the data processing agreement.
Legal provisions
- Art. 32 GDPR
- Security of processing.
- Arts. 24 and 25 GDPR
- Responsibility and data protection by design.
- Art. 30(1)(g) GDPR
- Description of the TOMs in the record of processing activities.