Technical and organisational measures (TOMs)
Technical and organisational measures (TOMs) is the GDPR's generic term for the safeguards that controllers and processors must implement to ensure and demonstrate compliance and to protect personal data. The phrase appears throughout the Regulation: in Art. 24 (responsibility of the controller), Art. 25 (data protection by design and by default), Art. 28 (guarantees required of processors), Art. 32 (security of processing) and Art. 89 (safeguards for research). Technical measures act on systems and data; organisational measures act on people and processes; both must be appropriate to the risk, taking into account the state of the art and the costs of implementation.
A typical TOM catalogue, structured along the lines of Annex II of the standard contractual clauses or ISO/IEC 27001 Annex A, covers: pseudonymisation and encryption; confidentiality controls such as physical access control, logical access management, role-based permissions and multi-factor authentication; integrity controls such as input logging, change management and audit trails; availability and resilience through backups, redundancy, disaster recovery and business continuity; procedures for regular testing, vulnerability management and penetration testing; incident and breach management; data minimisation, quality, retention and deletion; portability and secure erasure; staff confidentiality undertakings and training; vendor and sub-processor governance; and certification or adherence to codes of conduct.
TOMs must be documented, not merely implemented: in general terms in the record of processing activities (Art. 30(1)(g)), specifically in the annex to each data processing agreement, per actor in the DPIA, and in the transfer impact assessment where they serve as supplementary measures. In health and clinical research, regulators expect measures aligned with the CNIL security guide, ENISA health guidance, HDS hosting requirements and, for trial systems, 21 CFR Part 11 and the EMA computerised-systems guideline. iliomad's DPIA methodology scores each sponsor and vendor's TOMs on a three-point scale to identify where measures are acceptable, improvable or unacceptable.
