Technical and Organizational Measures (TOMs): A Guide to GDPR Compliance

- TOM ensure the security of personal data in accordance with Art. 32 GDPR and Section 64 BDSG.
- 14 control areas include access, entry, storage, and input controls, as well as encryption.
- Risk-based documentation and regular effectiveness testing are legally mandatory.
- Fines of up to 10 million euros or 2% of annual turnover may be imposed for violations.
- Proliance 360 supports you in the implementation, documentation, and continuous auditing of your TOM.
What are technical and organizational measures under the GDPR?
Technical and organizational measures (TOMs) are safeguardsthat controllers must implement to ensure the security of personal data. They form the core of data protection by design (Privacy by Design) and data protection by default (Privacy by Default).
Article 32 GDPR: The GDPR mandates these measures
- Pseudonymization and encryption of personal data
- Ongoing assurance of the confidentiality, integrity, availability, and resilience of systems
- Restorability of data following a technical or physical incident
- Procedures for regular testing, assessment, and evaluation of the effectiveness of TOMs
These general requirements are supplemented by Section 64 BDSG provides further detail by defining 14 specific areas of control.
What is the purpose of technical and organizational measures?
TOMs are intended to ensure that personal data state-of-the-art is protected accordingly. These measures must be risk-based – the more sensitive the data, the higher the requirements.
Practical example: Backup strategy as a TOM
- Requirement: Data must be recoverable following a technical incident.
- Implementation: If you work with hard drives, you need a regular backup system (e.g., the 3-2-1 rule: 3 copies on 2 different media, 1 off-site).
- Risk without TOM: Irreparable data loss following hard drive failure, GDPR violation, potential fines.
This risk analysis is the first step in implementing TOMs and is essential for ensuring adequate data security.
The 14 control areas and examples of TOMs
Section 64 of the German Federal Data Protection Act (BDSG) defines 14 specific areas where companies must implement TOMs. Not all are equally relevant for every company – the key is an individual risk analysis.
Overview: All 14 TOM control areas according to Section 64 BDSG
💡 Important: It is not necessary to implement all 14 measures – but you must use a risk analysis to document which ones are relevant to your company.
Technical and organizational measures for data processing agreements (DPA): What needs to be considered?
If you hire service providers to process personal data on your behalf (e.g., cloud providers, payroll services), you are required to sign a Data Processing Agreement (DPA) .
TOM requirements in the DPA according to Art. 28 (3) GDPR
In accordance with Art. 28 (3) GDPR , the DPA must specifically detail the technical and organizational measures taken by the data processor. As the controller, you must:
✅ The service provider's TOMs review before signing the contract
✅ Ensure that these meet your level of protection
✅ Regularly monitor the effectiveness of the TOMs (e.g., through audits)
Link: Find out more about legally compliant DPA contracts in our DPA template.
How do you document TOMs in compliance with the GDPR? Step-by-step guide
The GDPR requires not only the implementation of TOMs, but also their complete documentation. Here is how to proceed:

Step 1: Conduct a risk analysis
- Identify all processing activities (record of processing activities pursuant to Art. 30 GDPR)
- Assess the risk to the rights and freedoms of data subjects
- Determine the required level of protection
Step 2: Select appropriate TOMs
- Select appropriate measures from the 14 control areas for each processing activity
- Consider the state of the art, costs, and the probability of occurrence
Step 3: Create a TOM directory and document implementation
- Create a TOM directory with specific measures
- Assign responsibility for each measure
- Document implementation dates
Step 4: Regular effectiveness review
- Review the effectiveness of your TOMs at least annually
- Adapt measures to new risks or technologies
- Document all changes
💡 Tip: Use standardized templates to simplify documentation and avoid errors.
Technical and organizational measures for home office and remote work
The increasing prevalence of home office work places special demands on technical and organizational measures. Typical risks:
❌ Third-party access to company devices
❌ Insecure Wi-Fi connections
❌ Lack of physical access controls
The 5 most important TOM measures for remote work
TOM vs. ISMS: What is the difference?
Many companies ask themselves: Aren't TOMs the same as an Information Security Management System (ISMS) according to ISO 27001?
The key differences between TOM and ISMS
💡 Leverage synergies: An existing ISMS already covers many TOM requirements. However, data protection-specific measures (e.g., data subject rights, purpose limitation) must be added.
What are the penalties for TOM violations?
While other GDPR violations carry a maximum fine of 300,000 euros, TOM violations can be significantly more expensive:
Fine framework under Art. 83 (4) GDPR:
- Up to 10 million euros or
- 2% of the total worldwide annual turnover (whichever is higher)
Typical TOM violations with fine risks
❌ Missing or inadequate TOM
❌ No risk analysis conducted
❌ Inadequate documentation
❌ No regular effectiveness reviews
Case study: Fine due to lack of encryption
Example: A company stores customer data unencrypted and without access controls. Following a hacker attack, the data is leaked publicly. In addition to reputational damage, the company faces a heavy fine for violating Art. 32 GDPR.
💡 Important: Supervisory authorities do not just check if TOMs exist, but also whether they are appropriate and effective .
Conclusion: TOMs are the foundation of GDPR compliance
Technical and organizational measures are not optional, but a legal requirement. They protect not only personal data, but also your company from fines, liability risks, and reputational damage.
The 4 most important steps for implementing TOMs
- Risk assessment implement
- Select appropriate TOMs from the 14 control areas
- Document comprehensively (TOM directory, audit logs)
- Review regularly and adjust
With the right strategy and the right tools, you can implement TOMs efficiently – and create a solid foundation for lasting data protection.
Still have questions? We have the answers.
TOMs are GDPR-mandated measures for the security of personal data, such as building access controls or contractual controls like data processing agreements.
Companies that collect, process, or store personal data must implement TOMs, regardless of their size.
Technical and organizational measures (TOM) are designed to help ensure the protection of personal data. These are safeguards for various business areas that handle sensitive data. Examples of TOM include access controls for server rooms or the use of firewalls and backups.
Technical and organizational measures (TOM) are designed to provide the best possible protection for personal data collected, processed, and stored by companies. Key considerations include preventing unauthorized third-party access, data alteration, and safeguarding against unauthorized copying or deletion.
Technical and organizational measures include, for example, access controls, as well as controls over data transfer and input. All these measures aim to ensure that unauthorized third parties cannot gain access to data processing facilities, such as a server room. Further TOMs also include the use of file encryption, firewalls, antivirus programs, or backups. All these measures must always be implemented in accordance with the latest technological standards.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.












