Skip to main content
Category: Special Category Data

Suitable and Specific Measures

Also known as: Suitable and specific safeguards
Simply put

Suitable and specific measures are protective steps that organisations may be required to put in place when they process certain sensitive types of personal data, so that individuals' rights and interests are properly safeguarded. What counts as suitable depends on the particular purpose and context of the processing, so there is no single fixed checklist. In some situations, national law and regulator guidance set out which measures are expected.

Formal definition

The phrase 'suitable and specific measures to safeguard the fundamental rights and the interests of the data subject' appears in the context of conditions for processing that require additional protection, and is elaborated in domestic and member state implementing law rather than being fully specified in the operative GDPR text alone. For example, Section 36 of the Irish Data Protection Act 2018 requires that suitable and specific measures be taken to safeguard the fundamental rights and freedoms of data subjects, and sector-specific instruments (such as rules governing health research) can prescribe particular measures, which may include obtaining explicit consent. The measures required are context-dependent and tied to the specific purpose of processing; the ICO notes that whether a given measure is appropriate depends on the purposes, so techniques such as data minimisation or anonymisation may be suitable in some contexts and inappropriate in others. Practitioners should note that the precise catalogue of measures, and whether they are mandatory, varies with the applicable legal basis, the relevant special category or sensitive-data condition, and national derogations; readers should verify the specific requirements against the current official text of the applicable Regulation and implementing law, as the position can differ between the EU GDPR, the UK GDPR, and individual member state law.

Why it matters

Certain categories of personal data attract heightened protection because their misuse can cause significant harm to individuals. Where processing engages these sensitive categories, a controller cannot rely on generic security controls alone; it may be required to demonstrate that it has taken measures specifically tailored to safeguard the fundamental rights and interests of the data subject. Failing to identify and document the appropriate measures can undermine the lawfulness of the processing, particularly where a national implementing provision makes such measures a condition of relying on a given legal basis or special category condition.

The concept matters in part because it is not fully specified in the operative GDPR text and is instead elaborated in member state and domestic implementing law. This creates real divergence: for example, Section 36 of the Irish Data Protection Act 2018 requires that suitable and specific measures be taken to safeguard the fundamental rights and freedoms of data subjects, and sector-specific instruments governing health research can prescribe particular measures, which may include obtaining explicit consent. An organisation operating across the EU, the UK, and individual member states cannot assume a single approach will satisfy every regime.

Because what is suitable depends on the purpose and context of the processing, there is no fixed checklist that guarantees compliance. The ICO notes that whether a measure is appropriate depends on the purposes, so a technique such as data minimisation or anonymisation may be a suitable safeguard in one context yet inappropriate in another. Practitioners should treat the identification of measures as a documented, context-specific assessment rather than a box-ticking exercise, and verify the precise requirements against the current official text of the applicable Regulation and implementing law.

Who it's relevant to

Data Protection Officers and compliance leads
DPOs and compliance teams are typically responsible for identifying which safeguards apply to sensitive processing activities and documenting why they are suitable for the specific purpose. Because the required measures can be set out in national implementing law rather than the GDPR text alone, they should map each relevant processing operation to the applicable legal basis, special category condition, and any national derogation, and verify the requirements against the current official text.
Privacy and data protection lawyers
Lawyers advising on sensitive-data processing need to distinguish between measures that are legally mandatory under a domestic provision and those that are recommended good practice. Divergence between the EU GDPR, the UK GDPR, and member state law, such as the specific requirements under Section 36 of the Irish Data Protection Act 2018, means advice must be grounded in the applicable jurisdiction's implementing law rather than a single generic standard.
Health and research organisations
Organisations processing personal data for health research are particularly affected because sector-specific instruments can prescribe particular suitable and specific measures, which may include obtaining explicit consent. Such bodies should confirm the precise conditions that apply to their processing, as the catalogue of required measures and whether they are mandatory can vary with the applicable law.
Engineers and data architects
Technical teams implement many of the safeguards in practice, but they should not assume that a given control is universally appropriate. As the ICO notes, whether a measure such as data minimisation or anonymisation is suitable depends on the purpose of the processing, so engineers should work with the DPO to select controls that fit the specific processing context rather than applying a fixed default.

Inside Suitable and Specific Measures

Safeguards for sensitive or high-risk processing
Suitable and specific measures are safeguards required in certain processing contexts, particularly where special category data under Article 9 or other sensitive processing is involved, or where member state law conditions such processing on the presence of appropriate protections. They are intended to be proportionate to the risks the processing poses to data subjects.
Technical measures
Measures of a technical nature such as encryption, pseudonymisation, access controls, and logging that reduce the likelihood or severity of harm. The specific measures appropriate in a given case are subject to a risk-based assessment rather than fixed by a universal checklist.
Organisational measures
Governance and process controls such as staff training, confidentiality obligations, restrictions on internal access, designation of responsible persons, and documented policies. These complement technical measures and are assessed for suitability against the context of processing.
Context-dependent specificity
The requirement that measures be both suitable (appropriate to the nature and purpose of the processing) and specific (targeted to the identified risks), rather than generic. What qualifies depends on the processing activity, the categories of data, and the affected individuals.
Link to national implementing law and derogations
Suitable and specific measures frequently appear as a condition attached to member state derogations or national provisions permitting particular processing. Because member states may set differing requirements, the precise expectations can vary between jurisdictions and should be checked against the applicable national law and any regulatory guidance.

Common questions

Answers to the questions practitioners most commonly ask about Suitable and Specific Measures.

Does having a lawful basis under Article 6 mean I have satisfied the requirement for suitable and specific measures?
No. Suitable and specific measures are a distinct requirement that operates separately from identifying a lawful basis under Article 6. Where national law or a specific provision requires suitable and specific measures (for example, in the context of processing certain categories of data or processing subject to safeguards), those measures must be in place in addition to, not instead of, an appropriate legal basis. Treating the two as interchangeable is a common error. You should confirm both elements independently, and note that the precise measures expected can vary by member state where national implementing law applies.
Are suitable and specific measures the same thing as the technical and organisational measures required for security of processing?
Not exactly. There is overlap, because both can include technical and organisational controls, but they are not synonymous. Security-focused technical and organisational measures address the confidentiality, integrity, availability, and resilience of processing. Suitable and specific measures, as the phrase is used in certain provisions, are targeted safeguards intended to protect the interests and fundamental rights of data subjects in particular processing contexts. Some measures may serve both purposes, but you should not assume that meeting general security obligations automatically discharges a requirement for suitable and specific measures. The scope and expectation can differ, and national law may specify particular measures in given contexts.
How do I decide which suitable and specific measures are appropriate for a given processing activity?
The selection is generally context and risk dependent, and typically involves assessing the nature, scope, context, and purposes of the processing alongside the risks to the rights and freedoms of data subjects. In most cases you would document why particular measures were chosen and how they mitigate the identified risks. Where national implementing law or a specific provision lists or illustrates expected measures, those should be treated as a starting point. Because expectations can vary between member states and evolve through regulatory guidance, you should verify the current position for the relevant jurisdiction rather than relying on a fixed checklist.
Should suitable and specific measures be documented, and if so, where?
Documenting the measures is generally advisable to support accountability. In most cases the rationale for the chosen measures, and how they address the specific risks of the processing, can be recorded within records of processing activities, internal policies, or, where a data protection impact assessment is carried out, within that assessment. The appropriate location depends on your organisation's documentation structure. Where national law specifies documentation obligations, those should be followed. The aim is to be able to demonstrate, if asked, that the measures were considered and implemented for the specific processing in question.
Do suitable and specific measures need to be reviewed over time?
Typically yes. Because the adequacy of measures depends on the processing context and the associated risks, measures that are suitable at one point may become less so if the processing, the technology, the data involved, or the risk environment changes. In most cases it is prudent to review the measures periodically and when material changes occur, and to update them where the assessment indicates this is necessary. The appropriate review frequency is not fixed and should be proportionate to the risk; you should also check whether any applicable national law or guidance sets expectations.
Can the same set of suitable and specific measures be reused across different processing activities?
This should be approached with caution. Because the requirement is described as specific, measures are generally expected to be tailored to the particular processing and its risks rather than applied as a uniform template. Some baseline measures may be reusable where processing activities are genuinely comparable, but you should assess each activity on its own facts and confirm that reused measures actually address its specific risks. Where processing differs in nature, scope, context, purpose, or the categories of data involved, additional or different measures may be required, and national law variations may also affect what is expected.

Common misconceptions

Suitable and specific measures are a fixed, standardised list that applies identically to every organisation.
There is generally no single mandated checklist. The measures required are determined by a risk-based assessment of the specific processing, and what is suitable in one context may be insufficient or excessive in another. National law and regulatory guidance may also shape expectations differently across jurisdictions.
Meeting the suitable and specific measures requirement replaces the need for a lawful basis or an Article 9 condition.
These measures are typically an additional safeguard, not a substitute for a valid Article 6 legal basis, nor for the separate condition required to process special category data under Article 9. They operate alongside, rather than in place of, those requirements.
Implementing technical measures alone satisfies the requirement.
Suitable and specific measures generally encompass both technical and organisational safeguards. Technical controls without corresponding governance, access restrictions, and documented processes may leave the requirement only partially addressed, subject to assessment of the particular processing.

Best practices

Conduct and document a risk-based assessment of the specific processing to identify which technical and organisational measures are proportionate to the risks to data subjects.
Check the applicable national implementing law and any regulator guidance, since suitable and specific measures often derive from member state derogations that can vary between jurisdictions.
Confirm and record a valid Article 6 legal basis and, where special category data is involved, the applicable Article 9 condition, treating the measures as an additional safeguard rather than a replacement.
Combine technical controls such as encryption, pseudonymisation, and access restrictions with organisational controls such as training, confidentiality obligations, and documented policies.
Ensure measures are specific and targeted to the identified risks rather than relying on generic controls, and record the reasoning linking each measure to the risk it addresses.
Review the measures periodically and when the processing, data categories, or applicable law changes, and verify current requirements against the official text and up-to-date guidance.