Organisational Measures
Organisational measures are the internal policies, procedures, and staff practices an organisation puts in place to help keep personal data secure. Unlike technical measures such as encryption, they focus on how people and processes are managed, for example through staff awareness training, internal policies, and risk assessments. They are typically referred to alongside technical measures as part of a broader set of safeguards.
Organisational measures are the non-technical, process- and governance-oriented safeguards an organisation implements to protect personal data, forming one half of the concept of 'technical and organisational measures' (TOMs). Examples include carrying out an information risk assessment, establishing internal data security policies, and raising user or employee awareness. They are generally framed as 'appropriate technical and organisational measures' intended to ensure the requirements of the Regulation are met, with appropriateness assessed in context and by reference to risk. This entry describes the general concept; the precise obligations, applicable articles, and any national or UK GDPR variations should be verified against the current official text, and the specific measures required will depend on the circumstances of each processing operation.
Why it matters
Organisational measures are a foundational component of data security under the GDPR, which frames the obligation in terms of 'appropriate technical and organisational measures.' Technical controls such as encryption are only part of the picture; without policies, procedures, and trained staff to govern how personal data is handled, even strong technical safeguards can be undermined by human error or inconsistent practice. Because appropriateness is assessed in context and by reference to risk, organisations are generally expected to consider organisational measures alongside technical ones rather than treating either in isolation.
These measures matter because they translate abstract security requirements into day-to-day practice. An information risk assessment, for example, helps an organisation understand where its personal data is vulnerable, while internal policies and staff awareness efforts help ensure that people across the organisation act consistently to protect that data. The specific measures that are appropriate will depend on the circumstances of each processing operation, so this is not a fixed checklist but a risk-based exercise.
The precise obligations, applicable articles, and any national or UK GDPR variations should be verified against the current official text, as the appropriate combination of measures can vary by context and by regulator guidance.
Who it's relevant to
Inside Organisational Measures
Common questions
Answers to the questions practitioners most commonly ask about Organisational Measures.