Suitable and Specific Measures
Suitable and specific measures are protective steps that organisations may be required to put in place when they process certain sensitive types of personal data, so that individuals' rights and interests are properly safeguarded. What counts as suitable depends on the particular purpose and context of the processing, so there is no single fixed checklist. In some situations, national law and regulator guidance set out which measures are expected.
The phrase 'suitable and specific measures to safeguard the fundamental rights and the interests of the data subject' appears in the context of conditions for processing that require additional protection, and is elaborated in domestic and member state implementing law rather than being fully specified in the operative GDPR text alone. For example, Section 36 of the Irish Data Protection Act 2018 requires that suitable and specific measures be taken to safeguard the fundamental rights and freedoms of data subjects, and sector-specific instruments (such as rules governing health research) can prescribe particular measures, which may include obtaining explicit consent. The measures required are context-dependent and tied to the specific purpose of processing; the ICO notes that whether a given measure is appropriate depends on the purposes, so techniques such as data minimisation or anonymisation may be suitable in some contexts and inappropriate in others. Practitioners should note that the precise catalogue of measures, and whether they are mandatory, varies with the applicable legal basis, the relevant special category or sensitive-data condition, and national derogations; readers should verify the specific requirements against the current official text of the applicable Regulation and implementing law, as the position can differ between the EU GDPR, the UK GDPR, and individual member state law.
Why it matters
Certain categories of personal data attract heightened protection because their misuse can cause significant harm to individuals. Where processing engages these sensitive categories, a controller cannot rely on generic security controls alone; it may be required to demonstrate that it has taken measures specifically tailored to safeguard the fundamental rights and interests of the data subject. Failing to identify and document the appropriate measures can undermine the lawfulness of the processing, particularly where a national implementing provision makes such measures a condition of relying on a given legal basis or special category condition.
The concept matters in part because it is not fully specified in the operative GDPR text and is instead elaborated in member state and domestic implementing law. This creates real divergence: for example, Section 36 of the Irish Data Protection Act 2018 requires that suitable and specific measures be taken to safeguard the fundamental rights and freedoms of data subjects, and sector-specific instruments governing health research can prescribe particular measures, which may include obtaining explicit consent. An organisation operating across the EU, the UK, and individual member states cannot assume a single approach will satisfy every regime.
Because what is suitable depends on the purpose and context of the processing, there is no fixed checklist that guarantees compliance. The ICO notes that whether a measure is appropriate depends on the purposes, so a technique such as data minimisation or anonymisation may be a suitable safeguard in one context yet inappropriate in another. Practitioners should treat the identification of measures as a documented, context-specific assessment rather than a box-ticking exercise, and verify the precise requirements against the current official text of the applicable Regulation and implementing law.
Who it's relevant to
Inside Suitable and Specific Measures
Common questions
Answers to the questions practitioners most commonly ask about Suitable and Specific Measures.