General Description of Security Measures
A General Description of Security Measures is a summary of the technical and organisational steps an organisation takes to protect personal data. It is typically included in internal records and, in some cases, in contracts to show how information is kept secure, rather than providing exhaustive technical detail. Because specific requirements can vary by context and applicable law, the exact content and level of detail expected may differ, and readers should verify obligations against the current official text.
A General Description of Security Measures is a documented, high-level account of the technical and organisational measures implemented to ensure a level of security appropriate to the risk associated with processing personal data. In practice it commonly appears in two related contexts under the GDPR: as part of records of processing activities, where a controller's or processor's records are generally expected to contain, where possible, a general description of such measures; and as an annex or schedule to a data processing agreement between a controller and processor. Its scope is descriptive rather than prescriptive, and it should be distinguished from a full security policy, a risk or impact assessment, and any detailed technical specification. The appropriate content is assessed by reference to factors such as the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the risks to individuals; consequently, the required detail is context-dependent and subject to assessment. This definition reflects general GDPR concepts; because no external evidence was supplied, specific article references, member state derogations, and any divergence between the EU GDPR and UK GDPR positions should be verified against the current official text and applicable guidance.
Why it matters
A General Description of Security Measures is a practical expression of the GDPR's accountability principle: it is not enough to protect personal data, an organisation must generally be able to demonstrate the steps it has taken to do so. This description gives supervisory authorities, contractual counterparties, and internal stakeholders a concise reference point for understanding how personal data is safeguarded, without requiring disclosure of exhaustive or sensitive technical detail that could itself create risk if exposed.
The description also plays a distinct role in two common contexts. Within records of processing activities, it helps evidence that a controller or processor has considered security appropriate to the risk. As an annex or schedule to a data processing agreement, it allows a controller to understand and rely on the measures a processor has committed to, which supports the controller's own accountability obligations. Because the required level of detail is assessed against factors such as the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, the same document that is adequate for a low-risk activity may be insufficient for higher-risk processing.
Getting this description right matters because it is descriptive rather than prescriptive, and it should not be confused with a full security policy, a risk or impact assessment, or a detailed technical specification. Treating it as a substitute for those instruments, or copying a generic template without tailoring it to actual processing, can leave gaps that undermine both compliance posture and contractual reliance. The precise content and detail expected can vary by context and applicable law, so obligations should be verified against the current official text and applicable guidance.
Who it's relevant to
Inside General Description of Security Measures
Common questions
Answers to the questions practitioners most commonly ask about General Description of Security Measures.