Technical and Organisational Measures
Technical and organisational measures are the practical steps a company takes to keep personal data secure, covering both technology (such as controls on computers and networks) and the way people and processes are organised (such as policies and staff responsibilities). Under the EU and UK GDPR, both the organisation that decides how data is used and any organisation processing data on its behalf are expected to put appropriate measures in place based on the level of risk involved. What counts as appropriate depends on the specific circumstances rather than any single fixed checklist.
Under the EU GDPR (Art. 32) and correspondingly the UK GDPR, technical and organisational measures (TOMs) are the controls that data controllers and data processors are each required to implement to ensure a level of security of processing appropriate to the risk. Technical measures generally address the protection of personal data held in computers and networks, while organisational measures generally address policies, procedures, roles, and staff-related controls; both categories are treated together and neither alone is sufficient. Appropriateness is risk-based and contextual, so no specific control or combination is prescribed as universally mandatory or as guaranteeing compliance. Note the accountability principle: controllers and processors should generally be able to demonstrate that chosen measures are appropriate, not merely assert them. This entry addresses the security-of-processing concept only and does not cover cross-border transfer mechanics, retention obligations, breach-notification duties, or enforcement penalties; treatment under non-EU/UK regimes (for example the CCPA/CPRA, HIPAA, ISO/IEC 27701, or the NIST Privacy Framework) may differ and is out of scope here.
Why it matters
Technical and organisational measures sit at the heart of the security-of-processing obligation under the EU GDPR (Art. 32) and correspondingly the UK GDPR. Both data controllers and data processors are independently expected to implement measures appropriate to the risk, which means neither party can assume the other has covered security on its behalf. Because appropriateness is risk-based and contextual, there is no fixed checklist that guarantees compliance; the same set of controls may be adequate for one processing operation and insufficient for another involving more sensitive data or higher risk to individuals.
The distinction between technical and organisational measures matters in practice because each addresses a different dimension of security. Technical measures generally concern the protection of personal data held in computers and networks, while organisational measures concern policies, procedures, roles, and staff-related controls. Treating one as a substitute for the other is a common failing: strong encryption or network controls do not compensate for absent access-management policies or untrained staff, and vice versa. Both categories are treated together, and neither alone is regarded as sufficient.
Under the accountability principle, controllers and processors should generally be able to demonstrate that their chosen measures are appropriate rather than merely assert that measures exist. This evidential expectation is what distinguishes a defensible security posture from a stated intention. This entry addresses the security-of-processing concept only; it does not cover cross-border transfer mechanics, retention obligations, breach-notification duties, or enforcement penalties, and treatment under non-EU/UK regimes may differ.
Who it's relevant to
Inside TOMs
Common questions
Answers to the questions practitioners most commonly ask about TOMs.