{"id":73420,"date":"2026-08-05T22:34:47","date_gmt":"2026-08-05T20:34:47","guid":{"rendered":"http:\/\/adiumento.local\/?page_id=73420"},"modified":"2026-08-05T22:34:47","modified_gmt":"2026-08-05T20:34:47","slug":"technische-organisatorische-massnahmen","status":"publish","type":"page","link":"https:\/\/adiumento.de\/en\/themen\/regulatorik-sicher-umsetzen\/datenschutz-informationsschutz\/technische-organisatorische-massnahmen\/","title":{"rendered":"Technical and organisational measures"},"content":{"rendered":"<div class=\"wp-block-cover alignfull is-position-center-left service-page-hero is-light alignfull\" style=\"min-height:420px;aspect-ratio:unset;\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" class=\"wp-block-cover__image-background wp-image-73453\" alt=\"Datenschutz und Informationsschutz\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz.png\" data-object-fit=\"cover\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><span aria-hidden=\"true\" class=\"wp-block-cover__background has-dark-background-color has-background-dim-50 has-background-dim\"><\/span><div class=\"wp-block-cover__inner-container\"><p class=\"service-page-back is-layout-flow wp-block-cover-is-layout-flow\"><a href=\"https:\/\/adiumento.de\/en\/?page_id=73412\">\u2190 Data protection &amp; information protection<\/a><\/p><h1 class=\"wp-block-heading\">Technical and organisational measures<\/h1><p class=\"has-medium-font-size wp-block-paragraph\"><strong>Select TOMs based on risk, implement them in a comprehensible manner and keep them effective in operations.<\/strong><\/p><\/div><\/div>\n\n\n\n<div class=\"wp-block-group is-style-section-light service-page-orientation adiumento-passage is-layout-flow wp-block-group-is-layout-flow\"><p class=\"has-text-align-center service-orientation__text wp-block-paragraph\">Technical and organisational measures (TOMs) according to Art. 32 GDPR are not determined as a rigid checklist. Controllers and processors select them based on the risk to data subjects, the state of the art, implementation costs and the type, scope, circumstances and purposes of the processing. Clear responsibilities, documented decisions, technical implementation and regular effectiveness testing are crucial.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Relationship to services and technologies<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz.png\" alt=\"Datenschutz und Informationsschutz\" class=\"wp-image-73453 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-datenschutz-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">TOMs describe risk-related controls and their verifiability; they are not a blanket security product or a promise of conformity.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Background<\/h2>\n\n<p class=\"wp-block-paragraph\">Many companies already have security controls in place, but can only incompletely demonstrate their relationship to individual processing operations, risks and responsibilities. Access grows historically, configurations change and evidence lies in tickets, policies or individual teams. A list of measures alone therefore does not answer whether it is appropriate or whether it is actually being implemented.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">TOMs connect data protection, information security, specialist processes and IT operations. They are not a one-off project task: new applications, data flows, authorisations, security events and changed risks must flow back into the control system.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Technical context<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-governance-compliance-eu-ai-act-10.png\" alt=\"Abstrakte Illustration: Shield\/Check und Dokumente in Blau.\" class=\"wp-image-73216 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-governance-compliance-eu-ai-act-10.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-governance-compliance-eu-ai-act-10-300x225.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-governance-compliance-eu-ai-act-10-768x576.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-governance-compliance-eu-ai-act-10-16x12.png 16w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">Art. 32 GDPR requires appropriate measures, taking into account the state of the art and other contextual factors, to ensure a level of protection appropriate to the risk. The standard mentions, among other things, pseudonymization and encryption, confidentiality, integrity, availability and resilience of systems, recoverability and procedures for regular review, assessment and evaluation of effectiveness.<\/p>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The context goes further: the accountability according to Art. 5 Para. 2 and the responsibility according to Art. 24 GDPR require being able to provide evidence of the measures and decisions taken. Art. 25 GDPR requires data protection to be taken into account through technology design and data protection-friendly default settings when determining means and processing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Which measure is necessary or appropriate cannot be generally determined from a product name. The starting point is processing, data types, protection needs, threats, possible consequences for those affected and existing controls. The legal assessment of processing operations remains the responsibility of the responsible data protection and legal functions.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">What companies need to clarify specifically<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>Which processing, systems, interfaces and service providers are included in the scope under consideration?<\/li>\n<li>What risks to the rights and freedoms of data subjects arise from loss of confidentiality, integrity or availability?<\/li>\n<li>Who decides on risk acceptance, who implements measures and who checks their effectiveness?<\/li>\n<li>How are identities, permissions, endpoints, data, logs, backups and incidents controlled?<\/li>\n<li>What evidence supports the decision, implementation, change and regular monitoring?<\/li>\n<\/ul>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">From requirements to implementation<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1709\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-nachvollziehbare-entscheidungen-it-projekte-compliance-scaled.jpg\" alt=\"Managementteam trifft nachvollziehbare Entscheidungen in einem IT-Projekt anhand gemeinsamer Informationen.\" class=\"wp-image-73314 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-nachvollziehbare-entscheidungen-it-projekte-compliance-scaled.jpg 2560w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-nachvollziehbare-entscheidungen-it-projekte-compliance-300x200.jpg 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-nachvollziehbare-entscheidungen-it-projekte-compliance-1024x683.jpg 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-nachvollziehbare-entscheidungen-it-projekte-compliance-768x513.jpg 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-nachvollziehbare-entscheidungen-it-projekte-compliance-1536x1025.jpg 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-nachvollziehbare-entscheidungen-it-projekte-compliance-2048x1367.jpg 2048w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-nachvollziehbare-entscheidungen-it-projekte-compliance-18x12.jpg 18w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Limiting access<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Unauthorized inspection or modification<br><strong>Organisational measure:<\/strong> Role model, approvals, regular recertification<br><strong>Technical implementation:<\/strong> MFA, Least Privilege, Conditional Access<br><strong>Possible evidence:<\/strong> Role matrix, access reviews, protocols<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Protect data<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Disclosure in case of disclosure or loss<br><strong>Organisational measure:<\/strong> Classification model, specifications for release and external collaboration<br><strong>Technical implementation:<\/strong> Encryption, labels, DLP<br><strong>Possible evidence:<\/strong> Policy, label configuration, DLP events<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Ensure availability<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Loss or interruption<br><strong>Organisational measure:<\/strong> Restart and emergency procedures, responsibilities<br><strong>Technical implementation:<\/strong> Backups, recovery testing, monitoring<br><strong>Possible evidence:<\/strong> Test records, operational documentation<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Evaluate effectiveness<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Control only works on paper<br><strong>Organisational measure:<\/strong> Control plan, review dates, deviation management<br><strong>Technical implementation:<\/strong> Audit and security protocols, alerting<br><strong>Possible evidence:<\/strong> Review results, tickets, action status<\/p><\/details>\n<\/div>\n\n\n\n\n<p class=\"wp-block-paragraph\">A practical start is a risk-oriented inventory. It connects existing guidelines and technical configurations with the responsible process and system managers. This results in prioritised work packages instead of an unconnected target list.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">TOM evidence matrix<\/h2>\n\n<p class=\"wp-block-paragraph\">A uniform evidence line should be maintained for each relevant control:<\/p>\n\n\n\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Limit access to sensitive data<\/summary><p class=\"wp-block-paragraph\"><strong>Owner:<\/strong> System and process responsibility<br><strong>Scope:<\/strong> Systems, groups, data classes<br><strong>Configuration or process:<\/strong> Role model, approvals, access reviews<br><strong>Test method:<\/strong> Sampling and configuration testing<br><strong>Test interval:<\/strong> risk-based and when changes occur<br><strong>Result:<\/strong> documented test bench<br><strong>Deviation or action:<\/strong> Ticket, responsibility, date<\/p><\/details>\n<\/div>\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Limitations and dependencies<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-compliance-datenschutz-8.png\" alt=\"Abstrakte Illustration: Dokumente, DSGVO\/Compliance und Checkmark in Blau.\" class=\"wp-image-73239 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-compliance-datenschutz-8.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-compliance-datenschutz-8-300x225.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-compliance-datenschutz-8-768x576.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-compliance-datenschutz-8-16x12.png 16w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">TOMs cannot replace legal principles, transparency obligations or contracts for order processing. Their effectiveness also depends on complete inventories, maintained identities, resilient operational processes, sufficient resources and the consistent treatment of identified deviations. Individual products or configurations do not in themselves ensure conformity.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Further official sources<\/h2>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\">GDPR, in particular Articles 5 Para. 2, 24, 25 and 32<\/a> \u2013 EUR-Lex<\/li>\n<li><a href=\"https:\/\/www.bfdi.bund.de\/DE\/Fachthemen\/Inhalte\/Technik\/SDM.html\">Standard Data Protection Model<\/a> \u2013 BfDI \/ DSK<\/li>\n<li><a href=\"https:\/\/www.edpb.europa.eu\/documents\/guideline\/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en\">EDPB Guidelines 4\/2019 on data protection through technology design<\/a> \u2013 EDPB<\/li>\n<\/ul>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light service-page-topics adiumento-passage adiumento-themen-faq is-layout-flow wp-block-group-is-layout-flow\"><p class=\"has-text-align-center service-section-kicker wp-block-paragraph\">Orientation<\/p>\n<h2 class=\"wp-block-heading has-text-align-center\">Frequently asked questions<\/h2>\n\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Is an ISO or security standard sufficient as evidence of TOMs?<\/summary><p class=\"wp-block-paragraph\">A standard can provide structure and control objectives, but does not replace risk-related justification and evidence of the measures taken for specific processing operations. The context of processing and the actual implementation remain relevant.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">How often do TOMs need to be checked?<\/summary><p class=\"wp-block-paragraph\">Art. 32 GDPR mentions regular checking, assessment and evaluation. The appropriate rhythm depends, among other things, on risk, speed of change, incidents and type of control. Event-related checks supplement fixed review dates.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">What is the role of Microsoft 365 in TOMs?<\/summary><p class=\"wp-block-paragraph\">Microsoft 365 features can support technical controls for identity, devices, information protection, and logging. Their suitability depends on architecture, licenses, configuration, data flows and operations. The connections between identity, devices and access are covered <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-microsoft-umgebung\/entra-intune-conditional-access-compliance\/\">Entra, Conditional Access and Intune<\/a>; Identification and response treated <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-microsoft-umgebung\/defender-wdac-monitoring-incident-response\/\">Defender, app control, monitoring and incident response<\/a>.<\/p><\/details>\n<\/div>\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Next sensible step<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1344\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-daten-governance-grundlage-10.png\" alt=\"Abstrakte Illustration: Datenqualit\u00e4t und Governance als Fundament in Blau.\" class=\"wp-image-73217 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-daten-governance-grundlage-10.png 1344w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-daten-governance-grundlage-10-300x171.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-daten-governance-grundlage-10-1024x585.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-daten-governance-grundlage-10-768x439.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/05\/adiumento-daten-governance-grundlage-10-18x10.png 18w\" sizes=\"auto, (max-width: 1344px) 100vw, 1344px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">Start with a risk-oriented inventory and action planning for the most important processing and systems. The technical framework is below <a href=\"https:\/\/adiumento.de\/en\/loesungen\/\">IT Security &amp; Compliance<\/a> described; Legal and data protection functions evaluate the legal issues.<\/p>\n<\/div><\/div>\n\n\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Plan, implement, document and regularly assess TOMs in line with risk under Article 32 GDPR \u2013 without promising compliance.<\/p>","protected":false},"author":3,"featured_media":0,"parent":73412,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-73420","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/comments?post=73420"}],"version-history":[{"count":4,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73420\/revisions"}],"predecessor-version":[{"id":73506,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73420\/revisions\/73506"}],"up":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73412"}],"wp:attachment":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/media?parent=73420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}