The Meaning of Technical and Organisational Measures (TOMs)

Technical and Organisational Measures
GDPR

If you go through all of the 99 articles and the 173 recitals of the GDPR, you will read 89 times that you will need to have “appropriate technical and organisational measures”. They are in place to ensure the security of the personal data that you process. Despite the constant mention of this term, the GDPR is not so generous when it comes to defining or explaining what those measures can consist of. Therefore, we will explain what this means.

In general, as a data controller, you have the obligation to ensure the security of the personal data. This is in accordance with the principle of integrity and confidentiality. Having appropriate TOMs in place will help you prevent data breaches. You will also comply with the principle of data protection by design. In your record of processing activities, you should also include a general description of the TOMs you are applying. Additionally, you shall also use only processors that can provide essential guarantees that they have appropriate TOMs in place.

The Risk-Based Approach

Appropriate Technical and Organisational Measures Explained

Wherever you read about these measures in the GDPR, it is accompanied by the word “appropriate”. It is important you understand the meaning of “appropriate”. The requirement to use appropriate measures is good news. This is because that means that the GDPR does not require absolute security. It adopts a more pragmatic approach. That practically means that you are not breaching the GDPR every time you suffer a data breach. In other words operational failure does not equal legal failure. 

What you have to do, whether you are a controller or a processor, is to carry out risk assessments once you decide which measures you will apply. These measures must then be documented. Documentation is important for compliance with the principle of accountability. If you are a controller or a processor, you are required to demonstrate your compliance. 

For this assessment, you need to consider the following:

  • The nature of the personal data (whether special category, confidential, public etc)
  • Possible threats and vulnerabilities to your systems
  • What are the best practices, not the average?
  • Costs

Technical Measures

Technical and organisational measures are the measures and controls implemented to secure company systems. This can be devices, networks and hardware. Protecting such aspects is crucial for the security of personal data. It is the best line of defence against data breaches. However, other measures will be needed. We will cover these in organisational measures in addition to technical measures.

The most common technical measures you should consider are:  

  • Cyber security – At a simple level, firewalls, malware scans, anti-virus protection, patches and updating the software when required are the most common technical security measures to apply in order to safeguard the personal data you process against cyber attacks. 
  • Encryption and pseudonymisation – The GDPR is intentionally general when it comes to technical measures.
  • Physical security – Implement robust measures and protocols for securing access to any office or building and ensure that all employees are aware of such controls This will include CCTV, security lighting and alarms, and access logs. Visitor management must be a documented procedure.
  • Appropriate disposal –  Disposal of paperwork and devices that contain personal data must be permanent. Consider shredding documents that you no longer need and the secure disposal of digital databases and hardware devices. Ensure that your shredder has an suitable security level.
  • Passwords – Passwords must be part of the general Information Security strategy. A password policy is essential. Sensitive data documents must be password protected. However, never send this type of data via e-mail.
  • Access rights – You will ensure access to databases containing personal data is granted on a role-based policy. There should be no blanket access to all employees.

Organisational Measures

Organisational measures may consist of internal policies, methods or standards. Moreover, these will therefore be enforced by controls and audits. Equally important is that they may contribute to ensuring consistency in the protection of personal data throughout the full cycle of processing.

IT and Technical

  • Information security policies –  whose scope and content will depend on the size of the organisation and the type of processing activities. 
  • Business continuity plan – Your business must have a plan to allow the business to continue in the event of an incident.

Data Protection Culture

  • Risk assessments – Apart from being a legal requirement, risk assessments help develop mitigation solutions and are an effective preventive measure. 
  • Other policies and procedures – having robust and easy to follow policies and procedures helps an organisation and its employees to know what their obligations are and what to do if certain situations occur. Examples could include a clean desk, bring your own device, remote work policies, data breach or DSR procedures. 
  • Awareness & training – Developing a culture of security and data protection awareness is important. Security and data protection is for every employee and they all have a role to play. Regular and ongoing training as well as raising awareness activities can be effective measures.  
  • Reviews & audits – Having policies and procedures in place is not enough. You need to make sure that they are effective. Therefore, it is important to establish controls and audits to evaluate their effectiveness.
  • Due diligence – As a controller, you will be held liable if you use a non-compliant processor. They must be able to ensure the security of personal data. It is important to establish due diligence checks before you commit to a processor. You must agree with the processor a monitoring process.

In summary

Applying appropriate technical measures therefore has a central role in the GDPR. This is also illustrated by the fact that regulators across the EU issue fines when controllers fail to apply appropriate measures. The EU legislator is pragmatic and realistic. They do not require absolute security. However, you must endeavour to ensure the security of personal data you process. Proof is required. Risk assessments on a case-by-case basis are your tool to compliance!

Need help?

However, does this all sound a bit much? If you think it is, you are not alone. We help many businesses who are unsure of what technical measures are and how to implement them. Don’t forget that this is not just an IT problem.

We can carry out a technical measures audit to help you understand your current status. In the first instance, you can book your audit here. Alternatively you call us on 03333 22 1011 or contact us here.