Appropriate Technical and Organisational Measures
Appropriate technical and organisational measures are the safeguards an organisation puts in place to keep personal data secure and to show it is complying with data protection law. 'Technical' measures typically cover things like IT systems and controls, while 'organisational' measures cover things like internal policies, procedures, and staff arrangements. What counts as 'appropriate' depends on the risk involved, so there is no single fixed checklist that applies to every organisation.
Under the GDPR and UK GDPR, both controllers and processors are required to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32). The concept is risk-based rather than prescriptive: 'appropriate' generally means the measures should be calibrated to the nature, scope, context, and risks of the processing, as well as to the organisation's capacity to mitigate those risks. The requirement also operates within the broader accountability framework, where controllers are expected to adopt internal policies and implement measures demonstrating compliance (as reflected in Recital 78). Because the standard is context-dependent and assessed against evolving risk, no static set of controls guarantees compliance, and the specific measures considered adequate may vary and should be evaluated case by case and against current regulatory guidance. Article numbers and recital references should be verified against the current official text, and readers should note that the UK GDPR position may diverge from the EU GDPR over time.
Why it matters
Appropriate technical and organisational measures sit at the heart of the GDPR's security obligation. Under Article 32, both controllers and processors are required to ensure a level of security appropriate to the risk, and failure to do so is one of the most common triggers for regulatory scrutiny following a personal data breach. Because the obligation is framed around risk rather than a fixed list of controls, organisations cannot simply point to a certificate or a single tool and treat the matter as settled; they are expected to be able to justify why the measures chosen are appropriate to the specific processing.
The concept is also tied to the broader accountability framework. As reflected in Recital 78, controllers are expected to adopt internal policies and implement measures that demonstrate compliance, meaning TOMs are not only a defensive security requirement but also part of how an organisation shows it takes its obligations seriously. This dual function, protecting data and evidencing compliance, makes TOMs relevant both to day-to-day operations and to how an organisation would respond to a regulator's questions.
Because the standard is context-dependent and assessed against evolving risk, what is considered adequate can change over time and may be judged differently by different regulators. There is no static set of controls that guarantees compliance, and the specific measures expected should be evaluated case by case and against current regulatory guidance. Readers should verify the relevant article and recital references against the current official text and note that the UK GDPR position may diverge from the EU GDPR over time.
Who it's relevant to
Inside TOMs
Common questions
Answers to the questions practitioners most commonly ask about TOMs.