Technical and organisational measures (TOM) are how you turn "we take security seriously" into something a regulator can verify. Article 32 GDPR requires measures appropriate to the risk - and "appropriate" means specific and documented, not a sentence of good intentions. This checklist covers the technical and the organisational measures an SME needs, how detailed they have to be, and how they tie into your ROPA and data processing agreements.
- Art. 32 requires measures appropriate to the risk - the higher the sensitivity of the data, the more specific the TOM.
- "Appropriate measures" is a placeholder, not a control; name the encryption, the access model, the backup routine.
- TOM are referenced per ROPA entry and described in every DPA.
What Are Technical and Organisational Measures?
What does Article 32 actually require?
Article 32 requires you to protect personal data with measures appropriate to the risk - covering confidentiality, integrity, availability and resilience, plus the ability to restore access after an incident. It doesn't hand you a fixed list; it expects you to choose and document measures that fit your data and your risk. For most SMEs that means a clear, specific set of technical controls plus the organisational rules around them.
Technical Measures Checklist
Which technical measures do I need?
- Encryption - data in transit (TLS) and at rest (AES-256 or equivalent).
- Access control - only those who need access have it; roles and permissions documented.
- Backups - regular, tested backups with a defined recovery time.
- Logging - audit trails of who accessed which data, and when.
- Pseudonymisation - separating identifiers from content where feasible.
- Patch and endpoint management - systems kept updated; devices protected.
Organisational Measures Checklist
Which organisational measures do I need?
- Roles and responsibilities - who is accountable for each processing activity.
- Staff training - employees know how to handle personal data in their role.
- Deletion policy - what gets deleted, when, and by which process.
- Internal policies - BYOD, clean desk, password management.
- Incident response - who is notified and when, mapped to the 72-hour breach window.
- Vendor management - DPAs in place and TOM checked for each processor.
How Specific Do TOM Have to Be?
Is "appropriate security measures" enough?
No. "We apply appropriate measures" is a placeholder a regulator will reject. Specific is verifiable: "TLS 1.2+ in transit, AES-256 at rest, role-based access reviewed quarterly, daily tested backups with a 24-hour RTO." The more sensitive the data, the more detail you need. Use the checklist above as the skeleton and fill it with your actual configuration.
TOM Checklist (PDF)
How TOM Connect to Your ROPA and DPAs
Where do TOM sit in the documentation?
In your ROPA, each processing entry references the applicable TOM - inline or as a link to a TOM document. In every Data Processing Agreement, GDPR requires the processor's TOM to be described in sufficient detail; a DPA without specific TOM is incomplete. Keeping one current TOM document and referencing it everywhere is cleaner than repeating measures in each place.
documenting TOM once and keeping them tied to every process is exactly what ETHYX automates - your measures live in one place, referenced from each ROPA entry and DPA, and flagged when they fall out of date.