Glossary · Term

Technical and organisational measures (TOMs) explained

TOMs are the whole set of technical, operational and organisational measures for protecting information.

At a glance
Meaning
Technical, operational and organisational measures
Examples
Encryption, access rights, training
Origin
GDPR, fits NIS2 as well
Related
Controls
Updated
June 2026
Editorial team
Compliance Compass

What are TOMs?

Technical and organisational measures (TOMs) bring together all the protective measures of an organisation: technical ones (encryption, MFA), organisational ones (roles, Security policies, training) and operational ones (monitoring, maintenance). They are security put into practice. The wording comes from Article 32 of the GDPR; in international standards the same measures are called Controls – in substance the two mean the same thing.

The three dimensions

Technical versus organisational measures

The dividing line is simple. Technical measures work through technology, organisational ones through rules and people. Where one of them fails on its own, the other side catches the damage – which is why Article 32 of the GDPR and Article 21 of NIS2 both call for both columns, not only one.

Technical measuresOrganisational measures
Disk and transport encryption (TLS, VPN)Permission concept with documented roles
Multi-factor authentication (MFA) for administrative accountsTraining and awareness sessions for staff
Firewalls and network segmentationData processing agreements with service providers
Backups with tested restoresContingency and reporting process (24 h / 72 h / 1 month)
Logging and tamper protection for logsRegular review and approval of the Security policies

TOMs and controls

In substance TOMs are almost identical to the Controls of the international standards world, for example Annex A of ISO 27001. TOMs is simply the short collective name for them. If you document your measures cleanly once, you can use the same evidence for data protection and for cybersecurity instead of maintaining two separate catalogues.

TOMs under the GDPR and NIS2

The term comes from Article 32 of the GDPR, but it fits the NIS2 Directive just as well: both require appropriate technical and organisational measures to protect data and systems. The level of the sanction depends on the classification. Article 34 of NIS2 sets minimum fine ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts. Whether your entity also has to register, in what form and by when, follows from the national law that transposes the directive.

An example: An energy supplier keeps one central TOM overview. For data protection it serves as evidence under Article 32 of the GDPR; in a NIS2 inspection the same list – extended by the reporting chain of 24 hours for the early warning, 72 hours for the update and one month for the final report – is submitted as proof of its risk management, so that it can show the competent authority without gaps which measure addresses which concrete risk. One list is enough for both.

What do you need to do?

Further reading: GDPR Article 32 (EUR-Lex)

Frequently asked questions

What does TOMs stand for?

TOMs stands for technical, operational and organisational measures that protect information and systems. Technical measures include encryption, firewalls and multi-factor authentication (MFA); organisational ones cover roles, policies and training as well as contracts with service providers. Operational measures cover day-to-day running, that is monitoring, maintenance and regular testing. Together, TOMs are security put into practice.

Where are TOMs required?

The wording comes from Article 32 of the GDPR, which requires technical and organisational measures for data protection. Article 21 of the NIS2 Directive asks for the same in substance: appropriate measures to protect network and information systems. Article 34 sets minimum fine ceilings for infringements of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.

What is the difference between TOMs and controls?

In substance there is hardly any difference between TOMs and controls. TOMs is the collective short form for the technical and organisational measures of Article 32 of the GDPR; controls is the term used in standards such as ISO 27001 and its Annex A. Both mean concrete protective measures derived from the risk analysis. If you document your measures cleanly once, you can use the same evidence for data protection and for cybersecurity.

Measures

One TOM overview, two laws covered

Compliance Compass links every technical and organisational measure to the risk it addresses – one catalogue that holds up in a GDPR request just as well as in a NIS2 inspection.