Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

GDPR and IT security: technical requirements, TOMs and implementation

GDPR Article 32 requires technical security measures. This guide explains how to implement TOMs to meet compliance and protect personal data.

Summary: The EU General Data Protection Regulation (GDPR), in effect since May 2018, requires all companies that process the personal data of EU citizens to comply with its provisions. Fines of up to 4% of global annual revenue or €20 million - whichever is higher.

Sources & References

  1. [1] Datenschutz-Grundverordnung (EU) 2016/679 - EUR-Lex
  2. [2] BSI: Technische Maßnahmen nach Art. 32 DSGVO - BSI
  3. [3] ENISA: Pseudonymisation Techniques and Best Practices - ENISA

Questions about this topic?

Our experts advise you free of charge and without obligation.

Free Consultation

About the Author

Oskar Braun
Oskar Braun

Head of Information Security Consulting

E-Mail

Dipl.-Math. (WWU Münster) and doctoral candidate at the Promotionskolleg NRW (Hochschule Rhein-Waal), researching phishing awareness, behavioral security and nudging in IT security. Responsible for building and maintaining ISMS, leads internal audits to ISO/IEC 27001:2022 and advises as an external information security officer (ISB) in KRITIS sectors. Lecturer for Communication Security at Hochschule Rhein-Waal and NIS2 training lead at isits AG.

ISO 27001 Lead Auditor (IRCA) ISB (TÜV) T.I.S.P. (TeleTrusT)
This article was last edited on 03/29/2026. Responsible: Oskar Braun, Head of Information Security Consulting at AWARE7 GmbH. License: CC BY 4.0 - free use with attribution: "AWARE7 GmbH, https://a7.de"

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen