Technical and Organizational Measures (TOMs): A Guide to GDPR Compliance

Last updated:
05.03.2026
The General Data Protection Regulation (GDPR) requires companies to implement technical and organizational measures (TOMs) to ensure the secure processing of personal data. TOMs are the foundation of any GDPR-compliant data processing. In this guide, you will learn which measures are mandatory, how the 14 control areas work, and how to document your TOMs in a legally compliant manner—including practical tips for remote work and data processing agreements.
Technical and Organizational Measures (TOMs): A Guide to GDPR Compliance
Key Takeaways
  • TOM ensure the security of personal data in accordance with Art. 32 GDPR and Section 64 BDSG.
  • 14 control areas include access, entry, storage, and input controls, as well as encryption.
  • Risk-based documentation and regular effectiveness testing are legally mandatory.
  • Fines of up to 10 million euros or 2% of annual turnover may be imposed for violations.
  • Proliance 360 supports you in the implementation, documentation, and continuous auditing of your TOM.

What are technical and organizational measures under the GDPR?

Technical and organizational measures (TOMs) are safeguardsthat controllers must implement to ensure the security of personal data. They form the core of data protection by design (Privacy by Design) and data protection by default (Privacy by Default).

Article 32 GDPR: The GDPR mandates these measures

  1. Pseudonymization and encryption of personal data
  1. Ongoing assurance of the confidentiality, integrity, availability, and resilience of systems
  1. Restorability of data following a technical or physical incident
  1. Procedures for regular testing, assessment, and evaluation of the effectiveness of TOMs

These general requirements are supplemented by Section 64 BDSG provides further detail by defining 14 specific areas of control.

What is the purpose of technical and organizational measures?

TOMs are intended to ensure that personal data state-of-the-art is protected accordingly. These measures must be risk-based – the more sensitive the data, the higher the requirements.

Practical example: Backup strategy as a TOM

  • Requirement: Data must be recoverable following a technical incident.
  • Implementation: If you work with hard drives, you need a regular backup system (e.g., the 3-2-1 rule: 3 copies on 2 different media, 1 off-site).
  • Risk without TOM: Irreparable data loss following hard drive failure, GDPR violation, potential fines.

This risk analysis is the first step in implementing TOMs and is essential for ensuring adequate data security.

The 14 control areas and examples of TOMs

Section 64 of the German Federal Data Protection Act (BDSG) defines 14 specific areas where companies must implement TOMs. Not all are equally relevant for every company – the key is an individual risk analysis.

Overview: All 14 TOM control areas according to Section 64 BDSG

| Control area | Objective | Example measures | |---|---|---| | **Access control (entry)** | Prevent unauthorized persons from physically entering processing facilities | Chip cards, biometric scanners, locking systems | | **Data media control** | Prevent unauthorized reading, copying, alteration, or deletion | Encrypted USB drives, secure destruction of old storage media | | **Storage control** | Prevent unauthorized entry, viewing, alteration, or deletion | Access rights management, database encryption | | **User control** | Prevent unauthorized use of systems via data transmission | Two-factor authentication (2FA), VPN access | | **Access control (data)e** | Ensure only authorized persons can access their data | Role-based access control (RBAC) concepts | | **Transmission control** | Track where data has been transmitted to | Logging systems, recording of data exports | | **Input control** | Track who entered, changed, or deleted which data and when | Audit logs, database versioning | | **Transport control** | Protect confidentiality during transmission and transport | TLS/SSL encryption, secure courier services | | **Recoverability** | Restore systems in the event of a disruption | Regular backups, disaster recovery plan | | **Reliability** | Availability of all functions, error reporting | Monitoring tools, redundant systems | | **Data integrity** | Protection against damage caused by system errors | Error correction mechanisms, checksums | | **Job control (data processing agreements)** | Process data only in accordance with the controller's instructions | Data processing agreements (DPAs), training for data processors | | **Availability control** | Protection against destruction or loss | Redundant storage systems, fire protection in server rooms | | **Separability** | Process data collected for different purposes separately | Multi-tenant systems, separate databases |

💡 Important: It is not necessary to implement all 14 measures – but you must use a risk analysis to document which ones are relevant to your company.

Technical and organizational measures for data processing agreements (DPA): What needs to be considered?

If you hire service providers to process personal data on your behalf (e.g., cloud providers, payroll services), you are required to sign a Data Processing Agreement (DPA) .

TOM requirements in the DPA according to Art. 28 (3) GDPR

In accordance with Art. 28 (3) GDPR , the DPA must specifically detail the technical and organizational measures taken by the data processor. As the controller, you must:

✅ The service provider's TOMs review before signing the contract
✅ Ensure that these meet your level of protection
✅ Regularly monitor the effectiveness of the TOMs (e.g., through audits)

Link: Find out more about legally compliant DPA contracts in our DPA template.

How do you document TOMs in compliance with the GDPR? Step-by-step guide

The GDPR requires not only the implementation of TOMs, but also their complete documentation. Here is how to proceed:

Step-by-step guide to GDPR-compliant TOM documentation

Step 1: Conduct a risk analysis

  • Identify all processing activities (record of processing activities pursuant to Art. 30 GDPR)
  • Assess the risk to the rights and freedoms of data subjects
  • Determine the required level of protection

Step 2: Select appropriate TOMs

  • Select appropriate measures from the 14 control areas for each processing activity
  • Consider the state of the art, costs, and the probability of occurrence

Step 3: Create a TOM directory and document implementation

  • Create a TOM directory with specific measures
  • Assign responsibility for each measure
  • Document implementation dates

Step 4: Regular effectiveness review

  • Review the effectiveness of your TOMs at least annually
  • Adapt measures to new risks or technologies
  • Document all changes

💡 Tip: Use standardized templates to simplify documentation and avoid errors.

Technical and organizational measures for home office and remote work

The increasing prevalence of home office work places special demands on technical and organizational measures. Typical risks:

❌ Third-party access to company devices
❌ Insecure Wi-Fi connections
❌ Lack of physical access controls

The 5 most important TOM measures for remote work

| Area | Measure | |---|---| | **Access Control** | Screen locks with automatic activation, clean-desk policy | | **User Control** | VPN required for access to company data | | **Transmission Control** | Only encrypted communication channels (e.g., MS Teams, no private WhatsApp) | | **Media Control** | Encrypted hard drives on all endpoint devices | | **Training** | Regular awareness training for remote employees |

TOM vs. ISMS: What is the difference?

Many companies ask themselves: Aren't TOMs the same as an Information Security Management System (ISMS) according to ISO 27001?

The key differences between TOM and ISMS

| Aspect | TOM (GDPR) | ISMS (ISO 27001) | |---|---|---| | Focus | Protection of personal data | Protection of all company information | | Legal basis | GDPR (mandatory) | ISO standard (voluntary, but often required) | | Scope | Data protection-specific | Holistic IT security | | Certification | No official certification | ISO 27001 certification possible |

💡 Leverage synergies: An existing ISMS already covers many TOM requirements. However, data protection-specific measures (e.g., data subject rights, purpose limitation) must be added.

What are the penalties for TOM violations?

While other GDPR violations carry a maximum fine of 300,000 euros, TOM violations can be significantly more expensive:

Fine framework under Art. 83 (4) GDPR:

  • Up to 10 million euros or
  • 2% of the total worldwide annual turnover (whichever is higher)

Typical TOM violations with fine risks

❌ Missing or inadequate TOM
❌ No risk analysis conducted
❌ Inadequate documentation
❌ No regular effectiveness reviews

Case study: Fine due to lack of encryption

Example: A company stores customer data unencrypted and without access controls. Following a hacker attack, the data is leaked publicly. In addition to reputational damage, the company faces a heavy fine for violating Art. 32 GDPR.

💡 Important: Supervisory authorities do not just check if TOMs exist, but also whether they are appropriate and effective .

Conclusion: TOMs are the foundation of GDPR compliance

Technical and organizational measures are not optional, but a legal requirement. They protect not only personal data, but also your company from fines, liability risks, and reputational damage.

The 4 most important steps for implementing TOMs

  1. Risk assessment implement
  2. Select appropriate TOMs from the 14 control areas
  3. Document comprehensively (TOM directory, audit logs)
  4. Review regularly and adjust

With the right strategy and the right tools, you can implement TOMs efficiently – and create a solid foundation for lasting data protection.

Frequently Asked Questions

Still have questions? We have the answers.

What does 'TOM' mean in data protection?

TOMs are GDPR-mandated measures for the security of personal data, such as building access controls or contractual controls like data processing agreements.

Are Technical and Organizational Measures (TOM) mandatory for companies?

Companies that collect, process, or store personal data must implement TOMs, regardless of their size.

What are technical and organizational measures under GDPR?

Technical and organizational measures (TOM) are designed to help ensure the protection of personal data. These are safeguards for various business areas that handle sensitive data. Examples of TOM include access controls for server rooms or the use of firewalls and backups.

What is the purpose of technical and organizational measures?

Technical and organizational measures (TOM) are designed to provide the best possible protection for personal data collected, processed, and stored by companies. Key considerations include preventing unauthorized third-party access, data alteration, and safeguarding against unauthorized copying or deletion.

What are examples of technical and organizational measures?

Technical and organizational measures include, for example, access controls, as well as controls over data transfer and input. All these measures aim to ensure that unauthorized third parties cannot gain access to data processing facilities, such as a server room. Further TOMs also include the use of file encryption, firewalls, antivirus programs, or backups. All these measures must always be implemented in accordance with the latest technological standards.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Ivona Simic
Content & Social Media Manager
Ivona Simic is Content & Social Media Manager at Proliance. She is responsible for editorial content in the CMS, supports SEO & Content Marketing, and increases visibility. Her operational expertise includes organizing and executing online and offline events, managing collaborations, and developing and optimizing content for various digital channels. With a hands-on approach, she ensures efficient processes and successful campaigns.
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in