Skip to content

Article 32 GDPR: What TOMs Your Company Needs (and Why Training Is Part of It)

Provimedia Redaktion 6 min read 08 July 2026 2 views
Datenschutz & DSGVO
Article 32 GDPR: What TOMs Your Company Needs (and Why Training Is Part of It)
Illustrative image · AI-generated

Article 32 GDPR requires you, as controller, to protect personal data through appropriate technical and organizational measures (TOMs), matched to the risk for the data subjects. This includes technical safeguards such as encryption and access controls, as well as organizational measures such as deletion concepts, reporting channels, and documented employee training. You need to be able to justify and prove exactly this selection if things go wrong.

From the Provimedia editorial team · As of July 2026 · This article is general information, not legal advice.

After a reported data breach, the supervisory authority in practice asks one thing first: which TOMs did you already have in place and documented beforehand? This article shows you what Article 32 GDPR specifically requires. The table below helps you justify your selection if things go wrong.

What Does Article 32 GDPR Require?

Article 32(1) GDPR requires a level of protection appropriate to the risk for the processing of personal data. You must take into account the state of the art, the costs of implementation, and the nature, scope, context, and purpose of the specific processing.

  • lit. a) pseudonymization and encryption of personal data
  • lit. b) ongoing confidentiality, integrity, availability, and resilience of the systems
  • lit. c) rapid restoration of availability after a physical or technical incident
  • lit. d) a process for regularly testing and evaluating the effectiveness of the measures

Paragraph 2 names the risks you must protect against: destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data. Paragraph 4 adds that persons with access to data may only process it on the instructions of the controller. For you, this means: protect data not only from outside attacks, but also from mistakes and unauthorized access by your own employees.

An "appropriate" level of protection is not a rigid checklist of measures, but the result of a risk assessment. A one-person office with a customer list needs different TOMs than a practice handling health data.

This risk orientation is closely linked to the GDPR accountability obligation. Anyone who selects TOMs must also be able to justify and document that selection, not just claim to be appropriately protected.

What Counts as a Technical Measure, and What Counts as an Organizational One?

Technical measures act on systems, software, and infrastructure. Organizational measures act on processes, rules, and the behavior of your employees. Your TOM selection needs both levels together, as shown by the following overview with examples from the North Rhine-Westphalia State Commissioner for Data Protection and Freedom of Information (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, LDI NRW).

Type of MeasureExampleLegal Basis
TechnicalEncryption of data carriers and transmission pathsArt. 32(1)(a) GDPR
TechnicalRole and permission concept, firewall, up-to-date security updatesArt. 32(1)(b) GDPR
TechnicalRegular data backups and restoration testsArt. 32(1)(c) GDPR
OrganizationalProcess for regularly testing the effectiveness of the TOMsArt. 32(1)(d) GDPR
OrganizationalCommitting employees to confidentiality, binding them to instructionsArt. 32(4) GDPR
OrganizationalDeletion concept and retention periodsArt. 5(1)(e) GDPR
OrganizationalDocumented employee awareness and trainingArt. 32(1), Art. 24 GDPR

Why Is Employee Awareness Itself an Organizational Measure?

Article 32 GDPR expressly requires organizational safeguards too, not just technology. That is why the LDI NRW explicitly counts employee training among its recommended TOM examples. Encryption and a firewall, after all, do not protect you from an employee who reads out a password over the phone or emails a customer list to the wrong address.

Regular data protection instruction with documented participation is therefore itself a TOM within the meaning of Article 32(1) GDPR. At the same time, it supports your accountability obligation under Article 24 GDPR.

How Do Articles 32, 24, and 25 GDPR Connect?

Four provisions of the GDPR interlock for your TOMs. For you, that specifically means:

  • Art. 5(1)(f) GDPR: the "integrity and confidentiality" principle, meaning data must be protected against unauthorized processing, loss, and destruction.
  • Art. 32 GDPR: the specific security obligation, meaning choosing appropriate TOMs according to the risk.
  • Art. 24 GDPR: the accountability obligation, meaning documenting the choice of TOMs and their effectiveness.
  • Art. 25 GDPR: data protection by design, meaning building in protection from the start rather than adding it on afterward.

What Happens in Case of Violations of Article 32 GDPR?

Violations of Article 32 GDPR can be fined up to 10 million euros under Article 83(4)(a) GDPR. For companies, it is up to 2% of total worldwide annual turnover from the preceding financial year, whichever amount is higher. This range is lower than the fine range under Article 83(5) GDPR (up to 20 million euros or 4% of annual turnover), which applies, for example, to violations of the data processing principles under Article 5 GDPR.

In practice, this means: after a reported data breach, supervisory authorities regularly check whether appropriate TOMs, matched to the risk, were in place and documented. That is exactly the moment when your TOM documentation pays off.

Frequently Asked Questions (FAQ)

How Many TOMs Do I Need at Minimum?

The GDPR does not prescribe a fixed minimum number. Article 32(1) GDPR requires a level of protection appropriate to the risk, not a checklist. A one-person office with a customer list therefore needs different TOMs than a practice handling health data.

Does Article 32 GDPR Only Matter for Large Companies?

No: Article 32 GDPR applies to every controller and processor, regardless of company size. The text of the law expressly requires taking implementation costs and the nature of the processing into account. The scope of TOMs therefore scales with the risk and size of the business.

Is a One-Time Employee Training During Onboarding Enough?

The GDPR does not set a fixed repetition interval for data protection training. However, Article 32(1)(d) GDPR (regular testing of effectiveness) and the accountability obligation under Article 24 GDPR indirectly imply that recurring, documented awareness training is more appropriate than a one-time briefing during onboarding.

Do I Have to Document My TOMs in Writing?

Article 32 GDPR itself does not prescribe a specific documentation format. However, the accountability obligation under Article 24 GDPR requires that you be able to prove your TOMs. In practice, this happens through a TOM document for each processing activity, as part of the record of processing activities.

The documented awareness training of your employees, one of the organizational measures under Article 32 GDPR, is covered by our GDPR basic training with a dated certificate of participation. Your staff learn the basics of the GDPR in a practical way, and you receive traceable proof for your TOM documentation.

Sources

Share this article

Stay up to date

Get the latest articles, insights and industry updates straight to your inbox.

Unsubscribe at any time. See our privacy policy.

Decide for yourself what Google shows you

Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.

Add provimedia.de to my preferred sources

Bereit für den dokumentierten Schulungsnachweis?

Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.