Zum Hauptinhalt springen
Support
0
Kontaktieren Sie uns
English
Nederlands
Español
Dedicated ServersFlexible VPSCloud-TechnologieColocationHerausforderungen in der ITSektorenCareers
Cloud Compute

Mit Cloud Compute haben Sie jederzeit und überall Zugriff auf ein Portal, über das Sie Ihre gesamte IT-Umgebung konfigurieren können – egal wo auf der Welt Sie sich befinden.

Cloud-Speicher

Zuverlässiger Zugriff auf Ihre Dateien, Infrastruktur und Anwendungen zu jeder Zeit – ganz ohne Unterbrechungen oder Verzögerungen. Bei Worldstream bieten wir eine Vielzahl von Speicherlösungen an.

Flexible cloud icon
Flexible Cloud
Private cloud icon
Private Cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Objektspeicher
Hollow cube icon
Dateiablage
Block storage icon
Blockspeicher
Backup storage icon
Sicherungsspeicher
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Dedicated Server

Wählen Sie jetzt Ihren Dedicated Server. Individuelle oder Instant Delivery. Leistungsstarke Server, die perfekt zu Ihrem Anwendungsfall passen.

Use Cases

Ganz gleich, welcher Use Case – wir helfen Ihnen, die ideale Lösung zu finden.

Deal servers icon
Deals
AMD servers icon
AMD-Prozessoren
AI servers icon
Intel-Prozessoren
Hollow cube icon
Virtualisierung, Containerisierung & Orchestrierung
Hollow cube icon
Websites & Applications
Hollow cube icon
Gaming & Streaming Infrastruktur
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Smartes Outsourcing

Bestimmte IT-Lösungen generieren Mehrwert, andere erfüllen eher eine unterstützende Funktion. Denken Sie beim Outsourcing daran.

Kosteneffizienz

IT-Komplettpakete mögen erstmal wie eine sichere Option erscheinen, doch wenn man sich die Kosten genau anschaut, sind andere Lösungen oft sinnvoller.

IT-Flexibilität und Kontrolle

Outsourcing heißt nicht, dass man die Kontrolle verliert; man bekommt sogar mehr Flexibilität und Kontrolle.

Cloud-Repatriierung

Die Cloud ist kein Endziel: Sie sollten Ihre Cloud-Umgebung kontinuierlich prüfen und an die sich ändernden Anforderungen anpassen.

Finanzdienstleistungen
Logistik und Transport
Einzelhandel und E-commerce
Medien und Unterhaltung
Technik und Softwareentwicklung
Sicherheit
Managed Service Provider
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Chatten Sie mit unsKontaktieren Sie uns
Über WorldstreamÜber die TechnologieKundenfälleWissensdatenbank
Über unsLernen Sie unser Team kennenJobsWerden Sie WiederverkäuferZertifizierungenUnsere RechenzentrenUnser NetzwerkDDoS-SchutzAMD EPYC-ServerTechnologiepartnerBetriebssystemeAlle KundenfälleEasyTerraDutch Drone CompanyPerfGridArtikelFAQNachrichten und BlogbeiträgeProdukte und Services
Kontaktieren Sie uns

Rufen Sie an unter +31 (0) 174 – 712 117 Industriestraat 53, Naaldwijk

English
Nederlands
Español
0
Dedicated ServersFlexible VPSCloud-TechnologieColocationHerausforderungen in der ITSektorenCareersÜber WorldstreamÜber die TechnologieKundenfälleWissensdatenbankMy Worldstream
Contact
Support
EnglishNederlandsEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. Technical and organisational measures (TOMs): what they are

Technical and organisational measures (TOMs): what they are

Gilt für General concept, GDPR complianceZielgruppe Compliance-conscious customersZuletzt geprüft September 2026

Kort antwoord

Technical and organisational measures, usually shortened to TOMs, is a GDPR-derived term for the concrete safeguards a data processor has in place to protect personal data, things like access controls, encryption practices, staff training and incident response procedures. A provider's TOMs are typically documented and shared with customers, or required as part of a data processing agreement, so a customer can assess whether the provider's actual practices meet their own compliance needs.

Auf dieser Seite
  • What TOMs actually means
  • What's typically documented
  • TOMs vs. an SLA
  • TOMs vs. a certification

Anyone processing personal data on behalf of an EU organisation runs into the term TOMs sooner or later, usually while working through a data processing agreement (DPA) with a supplier. It's worth understanding clearly what it does and doesn't mean, because it gets confused with two other things suppliers commonly point to: an SLA and a certification.

What TOMs actually means

Technical and organisational measures is the GDPR's own phrase for the safeguards a data processor puts in place to protect the personal data it handles. "Technical" covers the mechanisms themselves, things like access controls, encryption of data at rest and in transit, logging, and network segmentation. "Organisational" covers the human and procedural side, staff training, defined roles and responsibilities, incident response procedures, and how access to data is granted and reviewed. Together, they're meant to describe, concretely, how a processor actually protects the data it's trusted with, not just that it has a policy saying it does.

In practice, a provider's TOMs are usually written down as a specific document, or a specific section of a data processing agreement, that a customer can read and assess. That's the whole point of the concept: it gives a customer something concrete to evaluate, rather than a general assurance.

What's typically documented

Exactly what appears in a TOMs document varies by provider and by the data being processed, but common categories include:

  • Access control: who can reach personal data, how access is granted, and how it's reviewed or revoked.
  • Encryption: whether and how data is encrypted at rest and in transit.
  • Staff training and confidentiality: how employees who might handle personal data are trained and bound to confidentiality.
  • Incident response: how a data breach or security incident is detected, escalated, and reported.
  • Physical security: controls over the physical environment where data-processing infrastructure lives.
  • Backup and resilience: how data is protected against loss, separate from how it's protected against unauthorised access.

TOMs vs. an SLA

An SLA (service level agreement) is a commitment about service performance, typically availability or support response. TOMs is a different kind of document entirely: it's specifically about how personal data is protected, and it belongs to the compliance and legal side of a relationship rather than the performance side. A provider can meet every figure in its SLA and still have weak TOMs, or the reverse, they answer different questions. If you're assessing a supplier for GDPR purposes, the SLA tells you almost nothing about whether their data protection practices meet your requirements, that's what the TOMs document is for.

TOMs vs. a certification

A certification is proof, audited by an independent third party, that a provider meets a specific named standard. TOMs, by contrast, is typically the provider's own documented description of its practices, it may or may not have been independently audited. That doesn't make TOMs less useful, a detailed, specific TOMs document is often exactly what a DPA requires, but it's a different kind of evidence than a certification. When you're evaluating a provider, it's worth being clear on which one you're actually looking at: a provider's own account of its practices, versus a third party's confirmation that those practices meet a defined standard.

Related articles

  • Data sovereignty: why it matters and what EU datacenters change
  • Value Added Tax (VAT) treatment
War dieser Artikel hilfreich?

Solide IT. Keine Überraschungen

Sparringspartner für IT-Reife
Wir räumen die Hindernisse aus dem Weg, damit Sie freie Bahn haben
Vorhersehbare und transparente Kosten

Kontakt

  • Industriestraat 53, Naaldwijk
  • Zahlungsmöglichkeiten
  • Missbrauch
  • Ressourcen für Entwickler
  • Network Operations Center
  • Über uns
  • Lernen Sie unser Team kennen
  • Jobs
  • Werden Sie Wiederverkäufer
  • Zertifizierungen
  • Unsere Rechenzentren
  • Unser Netzwerk
  • DDoS-Schutz
  • AMD EPYC-Server
  • Technologiepartner
  • Betriebssysteme
  • Übersicht
  • FAQ
  • Kundenfälle
  • Nachrichten und Blogbeiträge
  • Use Cases
English
Nederlands
Español
English
Nederlands
Español
  • Rechtliches
  • Transparenzhinweis