Measures Taken or Proposed
In data privacy, this phrase refers to the steps an organisation has already taken, or plans to take, to deal with a problem affecting personal data. It appears most notably when an organisation must report a personal data breach to a regulator, where it describes how the organisation is responding and trying to limit any harm. A closely related idea appears when an organisation assesses privacy risks in advance and sets out how it intends to reduce them.
A category of information that data controllers are generally required to document and communicate in specific accountability contexts under the EU GDPR. The phrasing 'measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects' appears as one of the elements to be included in a personal data breach notification to the supervisory authority under Article 33(3)(d). A distinct but conceptually related formulation, referring to the 'measures envisaged to address the risks,' appears in the context of a Data Protection Impact Assessment under Article 35(7)(d), where a controller must describe safeguards, security measures, and mechanisms proposed to mitigate identified risks to the rights and freedoms of data subjects. These are separate instruments serving different purposes: Article 33 concerns after-the-fact breach reporting, while Article 35 concerns prospective risk assessment; practitioners should not conflate the two. The precise wording, article numbering, and any national or UK GDPR variations should be verified against the current official text, as member state implementing law and regulator guidance may affect application. This entry addresses the term as used within the GDPR framework; unrelated uses of 'measure' (for example, ballot measures in electoral law) fall outside its scope.
Why it matters
The phrase "measures taken or proposed to be taken" is one of the required elements of a personal data breach notification to a supervisory authority under Article 33(3)(d) GDPR. It is significant because it shifts the focus of a breach report from what went wrong to how the controller is responding: containing the incident, limiting the spread of compromised data, and mitigating adverse effects on affected individuals. Regulators generally treat the quality and timeliness of these measures as an important signal of an organisation's accountability posture, and a well-documented response can be relevant to how a supervisory authority assesses the controller's overall handling of the incident.
A conceptually related but distinct formulation, "measures envisaged to address the risks," appears in Article 35(7)(d) GDPR as a required component of a Data Protection Impact Assessment. Here the emphasis is prospective rather than reactive: the controller sets out the safeguards, security measures, and mechanisms it proposes to reduce identified risks to the rights and freedoms of data subjects before high-risk processing begins. Practitioners should be careful not to conflate the two instruments. Article 33 concerns after-the-fact breach reporting under tight timelines, while Article 35 concerns forward-looking risk assessment; the same underlying vocabulary of "measures" serves different accountability functions in each.
Getting this element right matters for compliance because incomplete or vague descriptions of remedial or mitigating measures can undermine an otherwise timely notification, and because the two contexts carry different documentation expectations. The precise wording, article numbering, and any UK GDPR or national implementing variations should be verified against the current official text, since member state law and regulator guidance may affect how these requirements are applied in practice.
Who it's relevant to
Inside Measures Taken or Proposed
Common questions
Answers to the questions practitioners most commonly ask about Measures Taken or Proposed.