GDPR and IT security: technical requirements, TOMs and implementation
GDPR Article 32 requires technical security measures. This guide explains how to implement TOMs to meet compliance and protect personal data.
Summary: The EU General Data Protection Regulation (GDPR), in effect since May 2018, requires all companies that process the personal data of EU citizens to comply with its provisions. Fines of up to 4% of global annual revenue or €20 million - whichever is higher.
Sources & References
- [1] Datenschutz-Grundverordnung (EU) 2016/679 - EUR-Lex
- [2] BSI: Technische Maßnahmen nach Art. 32 DSGVO - BSI
- [3] ENISA: Pseudonymisation Techniques and Best Practices - ENISA
Questions about this topic?
Our experts advise you free of charge and without obligation.
About the Author
Dipl.-Math. (WWU Münster) and doctoral candidate at the Promotionskolleg NRW (Hochschule Rhein-Waal), researching phishing awareness, behavioral security and nudging in IT security. Responsible for building and maintaining ISMS, leads internal audits to ISO/IEC 27001:2022 and advises as an external information security officer (ISB) in KRITIS sectors. Lecturer for Communication Security at Hochschule Rhein-Waal and NIS2 training lead at isits AG.
3 Publikationen
- Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations Across Different Industries (2025)
- Self-promotion with a Chance of Warnings: Exploring Cybersecurity Communication Among Government Institutions on LinkedIn (2024)
- Exploring the Effects of Cybersecurity Awareness and Decision-Making Under Risk (2024)