Skip to main content
Category: Impact Assessments & Documentation

General Description of Security Measures

Also known as: General Description of Technical and Organisational Security Measures, General Description of the Technical and Organisational Measures
Simply put

A General Description of Security Measures is a summary of the technical and organisational steps an organisation takes to protect personal data. It is typically included in internal records and, in some cases, in contracts to show how information is kept secure, rather than providing exhaustive technical detail. Because specific requirements can vary by context and applicable law, the exact content and level of detail expected may differ, and readers should verify obligations against the current official text.

Formal definition

A General Description of Security Measures is a documented, high-level account of the technical and organisational measures implemented to ensure a level of security appropriate to the risk associated with processing personal data. In practice it commonly appears in two related contexts under the GDPR: as part of records of processing activities, where a controller's or processor's records are generally expected to contain, where possible, a general description of such measures; and as an annex or schedule to a data processing agreement between a controller and processor. Its scope is descriptive rather than prescriptive, and it should be distinguished from a full security policy, a risk or impact assessment, and any detailed technical specification. The appropriate content is assessed by reference to factors such as the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the risks to individuals; consequently, the required detail is context-dependent and subject to assessment. This definition reflects general GDPR concepts; because no external evidence was supplied, specific article references, member state derogations, and any divergence between the EU GDPR and UK GDPR positions should be verified against the current official text and applicable guidance.

Why it matters

A General Description of Security Measures is a practical expression of the GDPR's accountability principle: it is not enough to protect personal data, an organisation must generally be able to demonstrate the steps it has taken to do so. This description gives supervisory authorities, contractual counterparties, and internal stakeholders a concise reference point for understanding how personal data is safeguarded, without requiring disclosure of exhaustive or sensitive technical detail that could itself create risk if exposed.

The description also plays a distinct role in two common contexts. Within records of processing activities, it helps evidence that a controller or processor has considered security appropriate to the risk. As an annex or schedule to a data processing agreement, it allows a controller to understand and rely on the measures a processor has committed to, which supports the controller's own accountability obligations. Because the required level of detail is assessed against factors such as the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, the same document that is adequate for a low-risk activity may be insufficient for higher-risk processing.

Getting this description right matters because it is descriptive rather than prescriptive, and it should not be confused with a full security policy, a risk or impact assessment, or a detailed technical specification. Treating it as a substitute for those instruments, or copying a generic template without tailoring it to actual processing, can leave gaps that undermine both compliance posture and contractual reliance. The precise content and detail expected can vary by context and applicable law, so obligations should be verified against the current official text and applicable guidance.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads typically maintain or oversee records of processing activities, where a general description of security measures is generally expected where possible. They are usually responsible for ensuring the description is tailored to the actual risk of processing and kept current, and for distinguishing it from fuller instruments such as security policies and impact assessments.
Privacy and Commercial Lawyers
Lawyers drafting or negotiating data processing agreements frequently handle the general description of security measures as an annex or schedule. They need to ensure the description accurately reflects the measures a processor commits to, so that a controller can reasonably rely on it, while confirming precise obligations against the current official text and applicable guidance.
Controllers and Processors
Both controllers and processors may need to document a general description of security measures, whether in their own records of processing or within contractual arrangements between them. Controllers use it to understand and rely on a processor's safeguards; processors use it to communicate their measures at an appropriate, non-exhaustive level of detail.
Security and Engineering Teams
Engineers and security professionals often supply the substantive input for the description, translating implemented technical and organisational controls into a high-level summary. They help calibrate detail so the description reflects the state of the art and the actual risk without exposing sensitive specifics that a full technical specification would contain.

Inside General Description of Security Measures

Technical measures
The technological controls applied to protect personal data, which may include measures such as encryption, pseudonymisation, access controls, logging, and network security. The specific measures are not prescribed by the Regulation and are selected based on an assessment of risk.
Organisational measures
The governance, policy, and procedural controls that support data protection, such as staff training, internal policies, role-based access governance, incident response procedures, and vendor management. These complement technical measures and are also selected on a risk basis.
Risk-based calibration
A general description of security measures is expected to reflect the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, alongside the risk to the rights and freedoms of individuals. There is no fixed checklist that guarantees compliance; the appropriateness of measures is subject to assessment.
Confidentiality, integrity, availability, and resilience
Security of processing is generally framed around the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services, as well as the ability to restore access to data in a timely manner following an incident.
Testing and evaluation
A process for regularly testing, assessing, and evaluating the effectiveness of the measures. The description typically indicates that measures are reviewed over time rather than fixed at a single point.
Contextual role
A general description of security measures commonly appears as an annexed or summary component within instruments such as a Data Processing Agreement, and may be referenced in records of processing. It describes measures at a high level rather than reproducing full technical specifications.

Common questions

Answers to the questions practitioners most commonly ask about General Description of Security Measures.

Is a 'general description of the technical and organisational security measures' the same as a full security audit or certification?
No. A general description is a summary-level account of the safeguards in place, typically prepared to satisfy documentation and accountability expectations under the GDPR's security provisions. It is not itself an audit, penetration test, or certification. Certifications and audits are separate exercises that may support or evidence the measures described, but the general description does not require or substitute for them. The appropriate level of detail is generally assessed against the risk to individuals, the state of the art, and the costs of implementation, so what counts as adequate can vary by context.
Does providing a general description of security measures mean an organisation has proven it is fully compliant or fully secure?
No. Documenting security measures supports the accountability principle but does not by itself demonstrate full compliance or guarantee security. Security under the GDPR is generally assessed on a risk basis and is context dependent, so measures considered appropriate may change over time as risks and technology evolve. A description reflects the position at a point in time; it should be reviewed and updated, and it does not immunise an organisation against a finding that measures were inadequate in a given situation.
Where in an organisation's documentation does a general description of security measures typically appear?
It commonly appears in several places depending on the purpose. It is frequently included within records of processing activities as part of accountability documentation, within Data Processing Agreements between controllers and processors to describe the processor's safeguards, and in some cases within a Data Protection Impact Assessment where security is relevant to the risk analysis. The framing and level of detail generally differ by document, so organisations should tailor the description to the instrument in which it sits rather than reusing a single generic version everywhere.
How detailed should the description be?
There is no fixed template mandated by the Regulation. The appropriate level of detail is generally proportionate to the risk to individuals, the nature and scope of the processing, the state of the art, and implementation costs. In practice, descriptions often cover categories such as access controls, encryption or pseudonymisation where used, resilience and availability measures, and processes for testing and evaluating effectiveness. Organisations should avoid over-disclosing information that could itself create security risk, and calibrate detail to the audience and purpose of the document.
How often should a general description of security measures be reviewed or updated?
Because security is treated on an ongoing, risk-based footing, descriptions are generally reviewed periodically and when circumstances change, for example after a significant change to processing, a new technology deployment, a material change in risk, or following a security incident. There is no single review interval that applies universally; the timing typically depends on the risk profile and the organisation's own governance arrangements. Readers should confirm any specific cadence against internal policy and current regulatory guidance.
In a controller-processor relationship, whose responsibility is it to prepare the description?
Responsibilities differ by role. A processor typically describes the security measures it applies, often within a Data Processing Agreement, so the controller can assess whether they are appropriate. The controller generally remains responsible for satisfying itself that the processor provides sufficient guarantees and for its own security obligations across the processing it determines. Neither party's description discharges the other's independent obligations, and the precise allocation should be reflected in the contractual arrangements between them.

Common misconceptions

A general description of security measures must list a specific, mandated set of controls (for example, a particular encryption standard) to be valid.
The Regulation generally requires measures that are appropriate to the risk rather than prescribing a fixed list. Encryption and pseudonymisation are cited as examples, not as universal mandatory requirements. Appropriateness is context and risk dependent, and what is adequate can vary between processing activities.
Once a general description of security measures is documented, it demonstrates that the organisation is fully compliant and secure.
A description is a representation of the measures intended or in place, not proof of compliance or of security. Effectiveness must generally be tested and evaluated over time, and compliance depends on whether the measures remain appropriate to evolving risk. No description can be treated as guaranteeing compliance.
Security measures only concern technology and the responsibility of engineers.
Security of processing generally encompasses both technical and organisational measures. Organisational elements such as training, policies, and procedures are integral, and responsibility typically spans compliance, legal, and technical functions rather than resting with engineering alone.

Best practices

Frame the description around a documented risk assessment, tying each category of measure to the nature, scope, context, and purposes of the processing and to the risk to individuals, rather than copying a generic template.
Address both technical and organisational measures, and structure the description around confidentiality, integrity, availability, and resilience, including the ability to restore access after an incident.
Keep the general description at an appropriate level of detail for its purpose (for example, as an annex to a Data Processing Agreement) while maintaining more detailed internal documentation separately.
Establish and reference a process for regularly testing, assessing, and evaluating the effectiveness of the measures, and update the description when processing or risk changes.
Avoid absolute or guarantee-style language in the description; use qualified wording that reflects that measures are appropriate to assessed risk and subject to review.
Verify the description against the current official text and applicable guidance, and note where positions may differ under national implementing law or between the EU and UK regimes before relying on it.