Glossary term
GDPR Art. 32 TOMs
Also: Technical and organisational measures, Art. 32 GDPR, TOMs
Technical and organisational measures to ensure a level of security appropriate to the risk when processing personal data. Duty under Art. 32 GDPR, applicable to every controller and processor in the EU.
Art. 32 GDPR names four example areas: pseudonymisation and encryption, confidentiality/integrity/availability/resilience, restorability, regular evaluation. State of the art, cost of implementation, nature/scope/context/purposes of processing and risks are explicitly named as benchmarks.
Structuring: TOMs are usually documented by category (entry, access, use, transfer, input, processing, availability, separation control plus organisational measures such as training, confidentiality agreements, emergency management). Template structures are provided by German state data protection authorities and associations such as BvD or GDD.
Audit relevance: TOMs are a mandatory annex to data processing agreements under Art. 28 GDPR. Supervisors (federal and state data protection authorities) examine TOMs by sampling, systematically when an Art. 33 notification arrives. Generic TOM lists without specificity for the actual processing are a common deficiency example in supervisory publications.
Related terms
DPIA
Mandatory assessment under GDPR Art. 35 where processing is likely to result in high risk to the rig…
Schrems II
CJEU ruling of 16 July 2020 that invalidated the EU-US Privacy Shield and only allowed Standard Cont…
ISO 27001
International standard for information security management systems. Current version ISO/IEC 27001:20…
NIS2
EU directive on network and information security. Replaces NIS1, widens scope to around 30,000 Germa…
GPAI / Foundation Models
General-purpose AI models under EU AI Act Art. 51-56. Obligations from August 2025: technical docume…
AI Act Conformity Assessment
Procedure to demonstrate that a high-risk AI system complies with the EU AI Act before being placed …
AI Act Risk Categories
Four-tier classification under the EU AI Act: prohibited (Art. 5), high-risk (Annex I/III), limited …
Audit-ready decision
A decision whose record is structured, evidence-backed and stakeholder-signed to a level that a thir…
