Technical and organisational measures (TOMs) are the concrete precautions with which a company protects personal data — from encryption and access control to training and processes. The GDPR requires them in Article 32 as risk-appropriate security of processing.
In practice, TOMs meet every company twice: as their own duty — and as the annex of every data processing agreement, in which providers disclose their measures and customers assess them.
Which measures belong to the TOMs?
The usual structure follows protection goals: confidentiality (physical access, system access and data access control, encryption, separation of data sets), integrity (change traceability, input control), availability and resilience (backup, redundancy, DDoS protection, contingency concepts) plus procedures for regularly reviewing effectiveness.
Good TOMs are specific rather than generic: not encryption in place but which data, where, with which method; not access concept exists but how granting, recertification and offboarding actually run. Vague TOM lists are the first thing to stand out in audits.
TOMs in everyday business
- As a DPA annex: assess provider TOMs, keep your own current.
- As a living document: track changes to infrastructure and processes.
- As an audit basis: authorities and customers ask about effectiveness, not existence.
- Network measures count: segmentation, ZTNA and monitoring are TOMs.