Article 32 GDPR: What TOMs Your Company Needs (and Why Training Is Part of It)

Article 32 GDPR requires you, as controller, to protect personal data through appropriate technical and organizational measures (TOMs), matched to the risk for the data subjects. This includes technical safeguards such as encryption and access controls, as well as organizational measures such as deletion concepts, reporting channels, and documented employee training. You need to be able to justify and prove exactly this selection if things go wrong.
From the Provimedia editorial team · As of July 2026 · This article is general information, not legal advice.
After a reported data breach, the supervisory authority in practice asks one thing first: which TOMs did you already have in place and documented beforehand? This article shows you what Article 32 GDPR specifically requires. The table below helps you justify your selection if things go wrong.
What Does Article 32 GDPR Require?
Article 32(1) GDPR requires a level of protection appropriate to the risk for the processing of personal data. You must take into account the state of the art, the costs of implementation, and the nature, scope, context, and purpose of the specific processing.
- lit. a) pseudonymization and encryption of personal data
- lit. b) ongoing confidentiality, integrity, availability, and resilience of the systems
- lit. c) rapid restoration of availability after a physical or technical incident
- lit. d) a process for regularly testing and evaluating the effectiveness of the measures
Paragraph 2 names the risks you must protect against: destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data. Paragraph 4 adds that persons with access to data may only process it on the instructions of the controller. For you, this means: protect data not only from outside attacks, but also from mistakes and unauthorized access by your own employees.
An "appropriate" level of protection is not a rigid checklist of measures, but the result of a risk assessment. A one-person office with a customer list needs different TOMs than a practice handling health data.
This risk orientation is closely linked to the GDPR accountability obligation. Anyone who selects TOMs must also be able to justify and document that selection, not just claim to be appropriately protected.
What Counts as a Technical Measure, and What Counts as an Organizational One?
Technical measures act on systems, software, and infrastructure. Organizational measures act on processes, rules, and the behavior of your employees. Your TOM selection needs both levels together, as shown by the following overview with examples from the North Rhine-Westphalia State Commissioner for Data Protection and Freedom of Information (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, LDI NRW).
| Type of Measure | Example | Legal Basis |
|---|---|---|
| Technical | Encryption of data carriers and transmission paths | Art. 32(1)(a) GDPR |
| Technical | Role and permission concept, firewall, up-to-date security updates | Art. 32(1)(b) GDPR |
| Technical | Regular data backups and restoration tests | Art. 32(1)(c) GDPR |
| Organizational | Process for regularly testing the effectiveness of the TOMs | Art. 32(1)(d) GDPR |
| Organizational | Committing employees to confidentiality, binding them to instructions | Art. 32(4) GDPR |
| Organizational | Deletion concept and retention periods | Art. 5(1)(e) GDPR |
| Organizational | Documented employee awareness and training | Art. 32(1), Art. 24 GDPR |
Why Is Employee Awareness Itself an Organizational Measure?
Article 32 GDPR expressly requires organizational safeguards too, not just technology. That is why the LDI NRW explicitly counts employee training among its recommended TOM examples. Encryption and a firewall, after all, do not protect you from an employee who reads out a password over the phone or emails a customer list to the wrong address.
Regular data protection instruction with documented participation is therefore itself a TOM within the meaning of Article 32(1) GDPR. At the same time, it supports your accountability obligation under Article 24 GDPR.
How Do Articles 32, 24, and 25 GDPR Connect?
Four provisions of the GDPR interlock for your TOMs. For you, that specifically means:
- Art. 5(1)(f) GDPR: the "integrity and confidentiality" principle, meaning data must be protected against unauthorized processing, loss, and destruction.
- Art. 32 GDPR: the specific security obligation, meaning choosing appropriate TOMs according to the risk.
- Art. 24 GDPR: the accountability obligation, meaning documenting the choice of TOMs and their effectiveness.
- Art. 25 GDPR: data protection by design, meaning building in protection from the start rather than adding it on afterward.
What Happens in Case of Violations of Article 32 GDPR?
Violations of Article 32 GDPR can be fined up to 10 million euros under Article 83(4)(a) GDPR. For companies, it is up to 2% of total worldwide annual turnover from the preceding financial year, whichever amount is higher. This range is lower than the fine range under Article 83(5) GDPR (up to 20 million euros or 4% of annual turnover), which applies, for example, to violations of the data processing principles under Article 5 GDPR.
In practice, this means: after a reported data breach, supervisory authorities regularly check whether appropriate TOMs, matched to the risk, were in place and documented. That is exactly the moment when your TOM documentation pays off.
Frequently Asked Questions (FAQ)
How Many TOMs Do I Need at Minimum?
The GDPR does not prescribe a fixed minimum number. Article 32(1) GDPR requires a level of protection appropriate to the risk, not a checklist. A one-person office with a customer list therefore needs different TOMs than a practice handling health data.
Does Article 32 GDPR Only Matter for Large Companies?
No: Article 32 GDPR applies to every controller and processor, regardless of company size. The text of the law expressly requires taking implementation costs and the nature of the processing into account. The scope of TOMs therefore scales with the risk and size of the business.
Is a One-Time Employee Training During Onboarding Enough?
The GDPR does not set a fixed repetition interval for data protection training. However, Article 32(1)(d) GDPR (regular testing of effectiveness) and the accountability obligation under Article 24 GDPR indirectly imply that recurring, documented awareness training is more appropriate than a one-time briefing during onboarding.
Do I Have to Document My TOMs in Writing?
Article 32 GDPR itself does not prescribe a specific documentation format. However, the accountability obligation under Article 24 GDPR requires that you be able to prove your TOMs. In practice, this happens through a TOM document for each processing activity, as part of the record of processing activities.
The documented awareness training of your employees, one of the organizational measures under Article 32 GDPR, is covered by our GDPR basic training with a dated certificate of participation. Your staff learn the basics of the GDPR in a practical way, and you receive traceable proof for your TOM documentation.
Sources
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Phishing and Social Engineering: How Your Employees Can Spot an Attack
Phishing, spear phishing, CEO fraud, and smishing target people, not systems. The warning signs a phishing employee training should teach, and why a successful attack quickly turns into a reportable data breach.
GDPR Fines: Real Cases from Germany and What Companies Can Learn from Them
Four real GDPR fine cases from Germany show how authorities calculate the amount, and that courts can also significantly reduce them afterward.
Information Security Training vs. GDPR Training: What Companies Actually Need
Information security protects systems and information, data protection protects people and their data. The difference, the overlap under Art. 32 GDPR, and what the new NIS2 training duty means for management boards.
Bereit für den dokumentierten Schulungsnachweis?
Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.