Skip to main content
Category: Compliance and Monitoring

Technical and Organisational Measures

Also known as: TOMs, Technical and Organizational Measures, TOM
Simply put

Technical and organisational measures are the practical steps a company takes to keep personal data secure, covering both technology (such as controls on computers and networks) and the way people and processes are organised (such as policies and staff responsibilities). Under the EU and UK GDPR, both the organisation that decides how data is used and any organisation processing data on its behalf are expected to put appropriate measures in place based on the level of risk involved. What counts as appropriate depends on the specific circumstances rather than any single fixed checklist.

Formal definition

Under the EU GDPR (Art. 32) and correspondingly the UK GDPR, technical and organisational measures (TOMs) are the controls that data controllers and data processors are each required to implement to ensure a level of security of processing appropriate to the risk. Technical measures generally address the protection of personal data held in computers and networks, while organisational measures generally address policies, procedures, roles, and staff-related controls; both categories are treated together and neither alone is sufficient. Appropriateness is risk-based and contextual, so no specific control or combination is prescribed as universally mandatory or as guaranteeing compliance. Note the accountability principle: controllers and processors should generally be able to demonstrate that chosen measures are appropriate, not merely assert them. This entry addresses the security-of-processing concept only and does not cover cross-border transfer mechanics, retention obligations, breach-notification duties, or enforcement penalties; treatment under non-EU/UK regimes (for example the CCPA/CPRA, HIPAA, ISO/IEC 27701, or the NIST Privacy Framework) may differ and is out of scope here.

Why it matters

Technical and organisational measures sit at the heart of the security-of-processing obligation under the EU GDPR (Art. 32) and correspondingly the UK GDPR. Both data controllers and data processors are independently expected to implement measures appropriate to the risk, which means neither party can assume the other has covered security on its behalf. Because appropriateness is risk-based and contextual, there is no fixed checklist that guarantees compliance; the same set of controls may be adequate for one processing operation and insufficient for another involving more sensitive data or higher risk to individuals.

The distinction between technical and organisational measures matters in practice because each addresses a different dimension of security. Technical measures generally concern the protection of personal data held in computers and networks, while organisational measures concern policies, procedures, roles, and staff-related controls. Treating one as a substitute for the other is a common failing: strong encryption or network controls do not compensate for absent access-management policies or untrained staff, and vice versa. Both categories are treated together, and neither alone is regarded as sufficient.

Under the accountability principle, controllers and processors should generally be able to demonstrate that their chosen measures are appropriate rather than merely assert that measures exist. This evidential expectation is what distinguishes a defensible security posture from a stated intention. This entry addresses the security-of-processing concept only; it does not cover cross-border transfer mechanics, retention obligations, breach-notification duties, or enforcement penalties, and treatment under non-EU/UK regimes may differ.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads need to understand that TOMs are a shared, role-specific obligation falling on both controllers and processors under the EU and UK GDPR. They are typically involved in advising on whether chosen measures are appropriate to the risk and in ensuring the organisation can demonstrate that appropriateness under the accountability principle, rather than merely asserting it.
Information Security Teams
Security professionals generally own the technical measures, controls on computers and networks, but should recognise that technical controls alone are not sufficient under Art. 32. Effective TOMs require pairing technical controls with organisational measures such as policies, procedures, and staff responsibilities, which typically fall outside a purely security remit.
Data Processors and Vendors
Organisations processing personal data on behalf of others carry their own obligation to implement appropriate technical and organisational measures; they cannot assume the controller has addressed security for them. Processors should be prepared to demonstrate the appropriateness of their measures given the risk of the processing they perform.
Compliance and Governance Officers
Compliance and information governance leads are typically responsible for the organisational side of TOMs, policies, procedures, role definitions, and staff-related controls, and for maintaining the evidence needed to satisfy the accountability principle. They should treat appropriateness as contextual and risk-based rather than as a fixed checklist.

Inside TOMs

Technical Measures
Controls implemented through technology and system design, such as encryption, pseudonymisation, access controls, logging, and network security. These support confidentiality, integrity, and availability of personal data, though they overlap with but do not replace broader information security controls.
Organisational Measures
Governance and procedural controls, including policies, staff training, role definitions, access management processes, incident response procedures, and vendor management. These allocate responsibility and establish accountability rather than relying solely on technology.
Risk-Based Calibration
The expectation, generally expressed in the EU GDPR and mirrored in the UK GDPR, that measures be appropriate to the risk presented by the processing, taking into account the state of the art, cost of implementation, and the nature, scope, context, and purposes of processing. There is no fixed prescribed set of measures.
Allocation of Responsibility
Both data controllers and data processors bear obligations to implement appropriate technical and organisational measures. A controller determines purposes and means and remains accountable; a processor must implement measures on the controller's instructions and can be directly obligated in its own right.
Demonstrable Accountability
Under accountability principles, measures must be evidenced through documentation, testing, and records, not merely asserted. Stated intent alone is insufficient to demonstrate that appropriate measures are in place.

Common questions

Answers to the questions practitioners most commonly ask about TOMs.

Do technical and organisational measures only mean encryption and access controls?
No. This is a common misconception. Technical and organisational measures (TOMs) encompass far more than a handful of security technologies. The technical component can include controls such as encryption, pseudonymisation, access management, and logging, while the organisational component covers policies, staff training, role definitions, governance processes, vendor management, and documented procedures. Treating TOMs as a purely technical or security matter collapses the distinction between information security and data governance; both dimensions are generally required, and the appropriate mix depends on context and risk.
If we encrypt or tokenise the data, does it stop being personal data and remove our obligations?
No. Applying encryption or tokenisation as a technical measure does not, on its own, render data non-personal. Where the data can still be linked back to an individual, for example because a key or mapping exists that can reverse the transformation, it generally remains personal data and the associated obligations continue to apply. Such measures are risk-reducing safeguards rather than a route to placing data outside the scope of regulation. This is distinct from irreversible anonymisation, and the two should not be conflated.
How do we decide which technical and organisational measures are appropriate?
Appropriateness is typically assessed against the risk to individuals and the context of the processing, rather than against a fixed checklist. Factors generally weighed include the nature, scope, and purposes of the processing, the sensitivity of the data involved, the likelihood and severity of potential harm, and the state of available technology and cost of implementation. Because this is a risk-based judgement, measures suitable for one processing activity may be insufficient or excessive for another. This entry does not prescribe specific control sets, which vary by framework and implementation.
Who is responsible for implementing technical and organisational measures?
Responsibility generally sits with the party determining how and why data is processed and with any party processing data on its behalf, each in relation to their own obligations. Where processing is carried out by a processor, the controller typically remains accountable for ensuring adequate measures are in place, often reinforced through contractual arrangements, while the processor is expected to implement measures relevant to its role. The precise allocation depends on the relationship and the applicable instrument, and this entry does not address the detailed terms of controller-processor contracts.
How can we demonstrate that our technical and organisational measures are effective?
Under accountability-oriented frameworks, stated intent is generally not sufficient; demonstrable evidence is expected. In practice this typically means maintaining documentation of the measures adopted, the rationale for choosing them, and records of their operation, such as policies, procedures, testing outcomes, and review logs. The aim is to be able to show, if challenged, that measures were selected on a considered basis and are actually in effect. This entry does not cover specific audit or certification requirements, which differ across regimes.
How often should technical and organisational measures be reviewed?
Measures are generally treated as something to be reviewed and updated over time rather than set once, because risks, technology, and processing activities change. Reviews are typically prompted both on a periodic basis and in response to significant changes, such as new processing activities, incidents, or shifts in the threat landscape. The appropriate frequency depends on context and risk. This entry does not specify mandated review intervals, and any such requirements would depend on the applicable framework and internal policy.

Common misconceptions

Encryption or pseudonymisation renders data non-personal and therefore out of scope.
Encryption and pseudonymisation are technical measures that reduce risk, but pseudonymised data remains personal data because it can be reversed with additional information. Only irreversible anonymisation typically takes data out of most data protection scope, and even that is context-dependent.
Technical and organisational measures are the same as information security controls.
They overlap, particularly on confidentiality, integrity, and availability, but technical and organisational measures under data protection law also encompass governance, procedural, and accountability elements. Security is one component, not the whole obligation, and neither collapses into the other.
There is a fixed checklist of measures that guarantees compliance.
The obligation is risk-based and appropriate to the processing; no single control or predefined list guarantees compliance. Adequacy depends on context, jurisdiction, and implementation, and must be reassessed as risks and the state of the art change.

Best practices

Calibrate measures to the specific risk of each processing activity rather than applying a uniform baseline, and document the reasoning behind the chosen controls.
Maintain evidence of implemented measures, including policies, test results, and review records, so that accountability can be demonstrated rather than merely asserted.
Clearly allocate responsibilities between controller and processor in contractual arrangements, specifying which party implements and maintains which measures.
Treat pseudonymisation and encryption as risk-reduction measures while continuing to manage the underlying data as personal data.
Review and update measures periodically to reflect changes in the state of the art, cost, and the nature and context of processing.
Combine technical controls with organisational controls such as staff training, access governance, and incident response so that measures address both technology and human process.