Glossary · simply explained

TOMs (technical and organisational measures)

Technical and organisational measures (TOMs) are the concrete precautions with which a company protects personal data — from encryption and access control to training and processes. The GDPR requires them in Article 32 as risk-appropriate security of processing.

In practice, TOMs meet every company twice: as their own duty — and as the annex of every data processing agreement, in which providers disclose their measures and customers assess them.

Which measures belong to the TOMs?

The usual structure follows protection goals: confidentiality (physical access, system access and data access control, encryption, separation of data sets), integrity (change traceability, input control), availability and resilience (backup, redundancy, DDoS protection, contingency concepts) plus procedures for regularly reviewing effectiveness.

Good TOMs are specific rather than generic: not encryption in place but which data, where, with which method; not access concept exists but how granting, recertification and offboarding actually run. Vague TOM lists are the first thing to stand out in audits.

TOMs in everyday business

  • As a DPA annex: assess provider TOMs, keep your own current.
  • As a living document: track changes to infrastructure and processes.
  • As an audit basis: authorities and customers ask about effectiveness, not existence.
  • Network measures count: segmentation, ZTNA and monitoring are TOMs.

Frequently asked questions about TOMs (technical and organisational measures)

What does the GDPR specifically require for TOMs?

Article 32 requires measures appropriate to the risk of the processing — considering the state of the art and costs. Named as examples are encryption, pseudonymisation, resilience and recoverability plus regular effectiveness testing.

How detailed must TOM descriptions be?

Concrete enough that an auditor can assess effectiveness: methods, scope, owners. Pure buzzword lists count as a warning sign. At the same time, no security-critical details that would help attackers belong in them — the craft lies in the balance.

How often must TOMs be updated?

With every relevant change to systems, processes or providers — and reviewed periodically, at least annually as a rule. Outdated TOMs describing long-replaced systems are a classic finding in privacy audits.

What is the difference between TOMs and an ISMS?

TOMs are the concrete measures, the ISMS the steering framework above them: it decides risk-based which measures are needed and reviews their effectiveness. Whoever runs an ISMS generates their TOM documentation largely from it.

Do network and cloud security count as TOMs?

Yes, centrally: segmentation, access control via ZTNA, encryption in transit, DDoS protection, logging and monitoring are classic technical measures. With managed services, the provider’s measures belong in your own assessment via the DPA.

Want to put this into practice in your own network? Talk to KAEMI, aligned to your requirements and with a managed service from a single source.