Skip to main content
Category: Security & Breach Notification

Measures Taken or Proposed

Also known as: Measures taken or proposed to be taken, Measures envisaged to address the risks, Remedial measures (breach notification context)
Simply put

In data privacy, this phrase refers to the steps an organisation has already taken, or plans to take, to deal with a problem affecting personal data. It appears most notably when an organisation must report a personal data breach to a regulator, where it describes how the organisation is responding and trying to limit any harm. A closely related idea appears when an organisation assesses privacy risks in advance and sets out how it intends to reduce them.

Formal definition

A category of information that data controllers are generally required to document and communicate in specific accountability contexts under the EU GDPR. The phrasing 'measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects' appears as one of the elements to be included in a personal data breach notification to the supervisory authority under Article 33(3)(d). A distinct but conceptually related formulation, referring to the 'measures envisaged to address the risks,' appears in the context of a Data Protection Impact Assessment under Article 35(7)(d), where a controller must describe safeguards, security measures, and mechanisms proposed to mitigate identified risks to the rights and freedoms of data subjects. These are separate instruments serving different purposes: Article 33 concerns after-the-fact breach reporting, while Article 35 concerns prospective risk assessment; practitioners should not conflate the two. The precise wording, article numbering, and any national or UK GDPR variations should be verified against the current official text, as member state implementing law and regulator guidance may affect application. This entry addresses the term as used within the GDPR framework; unrelated uses of 'measure' (for example, ballot measures in electoral law) fall outside its scope.

Why it matters

The phrase "measures taken or proposed to be taken" is one of the required elements of a personal data breach notification to a supervisory authority under Article 33(3)(d) GDPR. It is significant because it shifts the focus of a breach report from what went wrong to how the controller is responding: containing the incident, limiting the spread of compromised data, and mitigating adverse effects on affected individuals. Regulators generally treat the quality and timeliness of these measures as an important signal of an organisation's accountability posture, and a well-documented response can be relevant to how a supervisory authority assesses the controller's overall handling of the incident.

A conceptually related but distinct formulation, "measures envisaged to address the risks," appears in Article 35(7)(d) GDPR as a required component of a Data Protection Impact Assessment. Here the emphasis is prospective rather than reactive: the controller sets out the safeguards, security measures, and mechanisms it proposes to reduce identified risks to the rights and freedoms of data subjects before high-risk processing begins. Practitioners should be careful not to conflate the two instruments. Article 33 concerns after-the-fact breach reporting under tight timelines, while Article 35 concerns forward-looking risk assessment; the same underlying vocabulary of "measures" serves different accountability functions in each.

Getting this element right matters for compliance because incomplete or vague descriptions of remedial or mitigating measures can undermine an otherwise timely notification, and because the two contexts carry different documentation expectations. The precise wording, article numbering, and any UK GDPR or national implementing variations should be verified against the current official text, since member state law and regulator guidance may affect how these requirements are applied in practice.

Who it's relevant to

Data Protection Officers and privacy leads
DPOs and privacy leads typically coordinate breach response documentation and DPIAs, so they need to distinguish the Article 33(3)(d) description of remedial and mitigating measures from the Article 35(7)(d) description of measures envisaged to address risks. They are often responsible for ensuring both are accurate, complete, and defensible if reviewed by a supervisory authority.
Incident response and security teams
Teams handling breach containment generate much of the factual basis for the "measures taken or proposed" element of a notification. Their records of containment, remediation, and steps to limit adverse effects on individuals feed directly into what the controller reports, subject to legal and DPO review.
Compliance and legal counsel
Counsel advising on GDPR accountability generally review breach notifications and DPIAs before submission, ensuring that descriptions of measures are neither overstated nor understated and that the two instruments are not conflated. They should verify current wording, article numbering, and any UK GDPR or national variations against official sources.
Controllers subject to accountability obligations
Organisations acting as data controllers bear the documentation and notification duties in which this phrase appears. They should maintain processes that capture measures both prospectively (DPIA) and reactively (breach notification), recognising that expectations may vary by regulator and member state implementing law.

Inside Measures Taken or Proposed

Statutory anchor in Article 33(3)(d) GDPR
The phrase 'measures taken or proposed to be taken' appears verbatim in Article 33(3)(d), which addresses personal data breach notifications to the supervisory authority. In this context it refers to the remedial and mitigating steps a controller has implemented, or plans to implement, to address the breach and to mitigate its possible adverse effects on data subjects.
Related formulation in Article 35(7)(d) GDPR
A closely related concept, 'the measures envisaged to address the risks', appears in Article 35(7)(d) as a required element of a Data Protection Impact Assessment. Here it captures the safeguards, security measures, and mechanisms proposed to demonstrate compliance and to reduce risks to the rights and freedoms of individuals. Practitioners should note this is a distinct instrument (a DPIA under Article 35) from a breach notification (Article 33).
Remedial versus preventive dimension
The term typically encompasses both measures already taken (actions completed at the time of reporting or assessment) and measures proposed to be taken (planned future actions). This forward- and backward-looking split is what distinguishes it from a static description of controls.
Mitigation of adverse effects
In the breach context, the measures generally include steps to mitigate possible adverse consequences for affected data subjects, which may be described qualitatively. The specific measures depend on the nature of the breach and are subject to a case-by-case risk assessment.
Accountability evidence
Documented measures support the accountability principle by evidencing that the controller (and, where relevant, the processor supporting it) considered and acted on identified risks. What qualifies as adequate is context-dependent and may be assessed differently by individual supervisory authorities.

Common questions

Answers to the questions practitioners most commonly ask about Measures Taken or Proposed.

Is "measures taken or proposed to be taken" a vague phrase with no specific basis in the GDPR?
No. The exact phrase "measures taken or proposed to be taken" appears verbatim in Article 33(3)(d) GDPR, which sets out what a personal data breach notification to the supervisory authority must contain. In that context it refers to the measures the controller has taken or proposes to take to address the breach, including, where appropriate, measures to mitigate its possible adverse effects. A closely related but distinct formulation, "the measures envisaged to address the risks," appears in Article 35(7)(d) GDPR in relation to the content of a Data Protection Impact Assessment. The two provisions are related in that both concern responsive or mitigating measures, but they arise in different processes and should not be treated as interchangeable. Readers should verify the precise wording against the current official text.
Does describing "measures taken or proposed to be taken" only apply to a DPIA under Article 35?
No. The verbatim phrase belongs to the breach notification requirements in Article 33(3)(d) GDPR, which apply once a controller becomes aware of a personal data breach and notifies the supervisory authority. Article 35(7)(d) GDPR uses the separate wording "measures envisaged to address the risks" as part of the minimum content of a DPIA, which is a forward-looking risk assessment carried out before or during processing likely to result in a high risk. Conflating the two can lead to documenting the wrong measures in the wrong instrument. It is generally advisable to identify which Article is engaged before drafting the relevant content.
What should the "measures taken or proposed to be taken" cover in a breach notification under Article 33?
Under Article 33(3)(d) GDPR, the notification should describe the measures the controller has taken or proposes to take to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. In practice this typically covers both containment or remediation steps already actioned and planned steps not yet completed. Because breaches are assessed case by case, the appropriate measures depend on the nature and severity of the breach. Where full information is not available at the time of the initial notification, the information may be provided in phases without undue further delay, subject to the requirements of Article 33.
How does documenting proposed measures differ between Article 33 and Article 35?
In the Article 33(3)(d) context, the measures are documented reactively in response to a specific breach and reflect what has been done and what is planned to address that incident. In the Article 35(7)(d) context, the DPIA records measures envisaged to address the risks identified in advance of or during high-risk processing, typically alongside safeguards, security measures, and mechanisms to ensure the protection of personal data. As a general matter, the DPIA is preventive and risk-focused, while the breach notification content is incident-focused. Organisations often maintain both types of records separately to reflect their distinct legal bases and timing.
If proposed measures are not yet implemented, can they still be included?
Yes. The phrasing "taken or proposed to be taken" in Article 33(3)(d) GDPR expressly contemplates measures that are planned but not yet complete, which is consistent with the ability to notify in phases where all information is not immediately available. Similarly, Article 35(7)(d) refers to measures envisaged, which are inherently prospective. It is generally good practice to distinguish clearly between measures already completed and those still in progress, and to update records as proposed measures are implemented, so that the documentation remains accurate over time.
Who is responsible for describing these measures?
For breach notifications under Article 33 GDPR, the obligation falls on the controller, which notifies the competent supervisory authority; a processor's role is generally to notify the controller of a breach without undue delay so the controller can meet its obligations. For a DPIA under Article 35 GDPR, the controller is responsible for carrying out the assessment and documenting the measures envisaged, and is required to seek the advice of the data protection officer where one has been designated. Allocation of responsibilities between a controller and processor should also be reflected in the relevant contractual arrangements, and specific positions can vary with national implementing law and the facts.

Common misconceptions

The phrase has no specific grounding in the GDPR and is only a generic compliance concept.
The exact phrase 'measures taken or proposed to be taken' appears verbatim in Article 33(3)(d) GDPR concerning breach notification, and a closely related formulation, 'measures envisaged to address the risks', appears in Article 35(7)(d) GDPR concerning DPIAs. It is therefore tied to specific Regulation text, though the two provisions serve different purposes.
The Article 33 breach-notification measures and the Article 35 DPIA measures are interchangeable.
They are distinct instruments. Article 33(3)(d) concerns remedial and mitigating measures in response to a personal data breach reported to the supervisory authority, while Article 35(7)(d) concerns measures envisaged to address risks identified during a Data Protection Impact Assessment. Conflating the two can misstate when and why each applies.
Listing measures in a breach notification or DPIA confirms the organisation is fully compliant.
Documenting measures evidences engagement with the accountability principle but does not by itself establish compliance. Adequacy is context- and risk-dependent and may be assessed by a supervisory authority; regulators can differ in their expectations, and guidance in this area continues to evolve.

Best practices

Identify which provision you are working under before drafting, since 'measures taken or proposed to be taken' (Article 33(3)(d)) and 'measures envisaged to address the risks' (Article 35(7)(d)) arise in different instruments and serve different objectives.
Distinguish clearly between measures already implemented and measures still proposed, so that a reader can see the current mitigation state versus planned follow-up.
In a breach notification, describe measures aimed at mitigating possible adverse effects on data subjects, tailored to the specific nature of the breach rather than relying on generic wording.
Retain documentation of the measures as accountability evidence, recording the reasoning and timing so the decision-making can be reconstructed if a supervisory authority asks.
Use qualified, factual descriptions rather than absolute claims of full compliance, recognising that adequacy is subject to case-by-case assessment.
Verify the precise article wording and any applicable supervisory authority guidance against the current official text, as expectations and guidance in this area can vary between regulators and evolve over time.