Skip to main content
Category: Security & Breach Notification

Organisational Measures

Also known as: Organizational Measures, TOMs (Technical and Organisational Measures)
Simply put

Organisational measures are the internal policies, procedures, and staff practices an organisation puts in place to help keep personal data secure. Unlike technical measures such as encryption, they focus on how people and processes are managed, for example through staff awareness training, internal policies, and risk assessments. They are typically referred to alongside technical measures as part of a broader set of safeguards.

Formal definition

Organisational measures are the non-technical, process- and governance-oriented safeguards an organisation implements to protect personal data, forming one half of the concept of 'technical and organisational measures' (TOMs). Examples include carrying out an information risk assessment, establishing internal data security policies, and raising user or employee awareness. They are generally framed as 'appropriate technical and organisational measures' intended to ensure the requirements of the Regulation are met, with appropriateness assessed in context and by reference to risk. This entry describes the general concept; the precise obligations, applicable articles, and any national or UK GDPR variations should be verified against the current official text, and the specific measures required will depend on the circumstances of each processing operation.

Why it matters

Organisational measures are a foundational component of data security under the GDPR, which frames the obligation in terms of 'appropriate technical and organisational measures.' Technical controls such as encryption are only part of the picture; without policies, procedures, and trained staff to govern how personal data is handled, even strong technical safeguards can be undermined by human error or inconsistent practice. Because appropriateness is assessed in context and by reference to risk, organisations are generally expected to consider organisational measures alongside technical ones rather than treating either in isolation.

These measures matter because they translate abstract security requirements into day-to-day practice. An information risk assessment, for example, helps an organisation understand where its personal data is vulnerable, while internal policies and staff awareness efforts help ensure that people across the organisation act consistently to protect that data. The specific measures that are appropriate will depend on the circumstances of each processing operation, so this is not a fixed checklist but a risk-based exercise.

The precise obligations, applicable articles, and any national or UK GDPR variations should be verified against the current official text, as the appropriate combination of measures can vary by context and by regulator guidance.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads are typically responsible for establishing and maintaining internal data security policies, coordinating information risk assessments, and driving staff awareness programmes. They need to understand organisational measures as a risk-based, context-dependent obligation rather than a fixed checklist, and to document how the chosen measures are appropriate to the processing involved.
Controllers and Processors
Organisations that collect, process, or use personal data, whether on their own behalf or on behalf of others, are generally expected to implement appropriate technical and organisational measures. Both controllers and processors have a stake in ensuring organisational safeguards such as internal policies and awareness practices are in place, though the precise allocation of responsibilities should be verified against the current official text and any applicable agreements.
Engineers and Security Teams
Technical teams that implement controls such as encryption benefit from understanding that organisational measures complement their work. Effective data security typically depends on process and governance safeguards, policies, risk assessments, and staff practices, working alongside technical controls, so security teams should coordinate with those managing the organisational side.
Legal Advisers
Lawyers advising on data security obligations need to frame organisational measures as part of the 'appropriate technical and organisational measures' standard, with appropriateness assessed in context and by reference to risk. They should flag that specific requirements depend on the processing operation and that national or UK GDPR variations may apply, verifying the position against the current official text.

Inside Organisational Measures

Policies and Procedures
Documented internal rules governing how personal data is handled, including data protection policies, retention schedules, and incident response procedures. These form the governance backbone that translates legal obligations into operational practice.
Staff Training and Awareness
Programmes to ensure personnel who process personal data understand their responsibilities. Training is generally considered a core organisational measure supporting the accountability principle, though its adequacy is assessed by reference to the risks presented by the processing.
Roles and Responsibilities
Clear allocation of accountability, including the designation of a Data Protection Officer where required, and the definition of reporting lines for privacy matters. This helps distinguish controller and processor obligations in practice.
Access Governance and Confidentiality Commitments
Organisational controls limiting who may access personal data on a need-to-know basis, and binding staff to confidentiality. These complement technical access controls rather than replacing them.
Vendor and Processor Management
Processes for selecting, instructing, and overseeing processors, typically underpinned by written contracts. Contractual arrangements with processors are addressed under Article 28, and organisational measures support the ongoing oversight such arrangements require.
Record-Keeping and Documentation
Maintaining records that demonstrate compliance, such as records of processing activities and evidence of decisions taken. Documentation supports the ability to demonstrate accountability upon regulator request.

Common questions

Answers to the questions practitioners most commonly ask about Organisational Measures.

Are organisational measures the same thing as technical measures under the GDPR?
No, though the two are closely linked and often referenced together in the phrase 'technical and organisational measures' (frequently abbreviated as TOMs) used in provisions such as those on security of processing. Technical measures generally relate to technology-based controls (for example, encryption, access controls, or logging), whereas organisational measures relate to governance, policies, procedures, training, and human and administrative controls. Both categories are expected to work together, and the appropriate combination is subject to a risk-based assessment considering the state of the art, costs, and the nature, scope, context, and purposes of processing. Neither category alone is treated as sufficient on its own.
Does implementing organisational measures by itself make an organisation compliant?
Not on its own. Organisational measures are one component of a broader accountability and security posture, and their presence does not, by itself, establish full compliance. Compliance is context and risk dependent, and organisational measures typically need to be appropriate to the specific processing, kept under review, and combined with technical measures and a valid legal basis for the processing. The adequacy of any given set of measures is assessed against the actual risks to individuals, so a documented policy that is not implemented or maintained may offer limited protection in practice.
How should we decide which organisational measures are appropriate for our processing?
The Regulation frames this as a risk-based exercise rather than a fixed checklist. In most cases you would consider the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, alongside the likelihood and severity of risks to individuals' rights and freedoms. Measures that are proportionate for high-risk processing may exceed what is expected for lower-risk activities. Because regulators may emphasise different factors and guidance evolves, it is advisable to document the reasoning behind your choices and review it against the current official text and any applicable guidance.
What are common examples of organisational measures?
Examples typically include internal data protection policies and procedures, staff training and awareness programmes, role and responsibility assignments, access management processes on the administrative side, vendor and processor management, incident and breach response procedures, record-keeping practices, and internal audit or review mechanisms. This list is illustrative rather than exhaustive, and the appropriate set of measures depends on the specific processing and the outcome of a risk assessment.
How do organisational measures relate to accountability?
Organisational measures generally support the accountability principle, under which a controller is expected not only to comply but to be able to demonstrate compliance. Governance structures, documented policies, records, and evidence of training and review can help demonstrate that appropriate measures were considered and implemented. The value of these measures for accountability purposes typically depends on them being documented, actually operationalised, and kept current, rather than existing only on paper.
How often should organisational measures be reviewed and updated?
The Regulation treats appropriate measures as something to be maintained rather than set once, and it generally contemplates ongoing testing, assessing, and evaluating of measures. There is no single universally mandated review interval stated as a fixed figure, so organisations commonly tie reviews to defined periods and to trigger events such as changes in processing activities, new risks, incidents, or organisational change. The appropriate cadence is a matter of assessment, and you should verify any specific requirements against the current official text and applicable guidance.

Common misconceptions

Organisational measures are optional add-ons once technical security controls are in place.
The GDPR refers to 'appropriate technical and organisational measures' together; the two are generally treated as complementary. Technical controls without supporting governance, training, and procedures are typically considered incomplete, and the appropriateness of measures is assessed against the risk in each context.
Having a written policy means the organisation is fully compliant.
A policy that is not implemented, communicated, or maintained provides limited value. Compliance is context and risk dependent, and regulators generally look for evidence that measures operate in practice, not merely that documents exist.
Organisational measures are identical for controllers and processors.
While both must implement appropriate measures, their obligations differ. Controllers and processors have distinct responsibilities under the Regulation, and the specific measures expected of each should be assessed by reference to their respective roles rather than assumed to be the same.

Best practices

Assess the measures you adopt against the specific risks of your processing rather than applying a fixed checklist, and document the reasoning behind the choices made.
Maintain policies as living documents by reviewing them periodically and after material changes to processing, and keep evidence that they are communicated and followed.
Deliver role-appropriate training to staff who handle personal data and record completion so you can demonstrate the measure in practice.
Define and document clear roles and responsibilities, including who is accountable for privacy decisions and where a Data Protection Officer is designated.
Integrate organisational measures with your technical controls so that governance, access limitation, and confidentiality commitments reinforce one another.
Verify the position under the applicable law, as requirements may differ between the EU GDPR, the UK GDPR, and national implementing measures, and confirm details against the current official text.