Technical Measures
Technical measures are the technology-based safeguards an organisation puts in place to protect personal data, such as security software, access controls, and secure storage. They are commonly discussed alongside organisational measures (the policies and procedures side) as part of a broader set often called 'technical and organisational measures'. Together they aim to keep personal data secure, though what is appropriate depends on the specific risks and context.
Technical measures are the system-, network-, and device-level controls implemented to protect personal data, typically encompassing information security features, secure data collection and storage, and protective software such as antivirus and access controls. In the GDPR context they form one half of the concept of 'technical and organisational measures' (TOMs), with organisational measures addressing governance, policy, and process. The specific measures considered appropriate are not fixed by a prescribed checklist but are assessed against the risk to individuals, the state of the art, implementation costs, and the nature, scope, context, and purposes of processing; readers should verify the applicable GDPR provisions and current regulatory guidance, as the required standard is risk-dependent and evolves. The term is distinct from unrelated technical-measurement concepts (for example, technical performance measurement or copyright-related standard technical measures) that appear under similar names in other fields.
Why it matters
Technical measures sit at the heart of the GDPR's security obligations, which generally require controllers and processors to implement appropriate safeguards to protect personal data. Because the Regulation does not prescribe a fixed checklist, technical measures matter precisely because they must be tailored: the same encryption or access-control approach that is adequate for low-risk processing may fall short where the risk to individuals is higher. Getting this balance wrong exposes organisations to regulatory scrutiny, and inadequate technical safeguards are frequently a contributing factor in the security incidents that draw enforcement attention.
The standard is deliberately risk-dependent. Regulators typically expect organisations to weigh factors such as the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the processing against the likelihood and severity of risk to individuals. This means technical measures are not a one-time procurement exercise but an ongoing assessment that should be revisited as threats, technologies, and processing activities change. What is considered adequate today may be viewed as insufficient later as the state of the art advances.
Technical measures are also rarely sufficient on their own. They are commonly framed as one half of 'technical and organisational measures' (TOMs), and technology controls generally need to be supported by governance, policies, and processes to be effective. Readers should treat any list of controls as illustrative rather than definitive, and verify the applicable GDPR provisions and current regulatory guidance, since the required standard evolves.
Who it's relevant to
Inside Technical Measures
Common questions
Answers to the questions practitioners most commonly ask about Technical Measures.