Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. Technical and organisational measures (TOMs): what they are

Technical and organisational measures (TOMs): what they are

Applies to General concept, GDPR complianceAudience Compliance-conscious customersLast reviewed September 2026

Quick answer

Technical and organisational measures, usually shortened to TOMs, is a GDPR-derived term for the concrete safeguards a data processor has in place to protect personal data, things like access controls, encryption practices, staff training and incident response procedures. A provider's TOMs are typically documented and shared with customers, or required as part of a data processing agreement, so a customer can assess whether the provider's actual practices meet their own compliance needs.

On this page
  • What TOMs actually means
  • What's typically documented
  • TOMs vs. an SLA
  • TOMs vs. a certification

Anyone processing personal data on behalf of an EU organisation runs into the term TOMs sooner or later, usually while working through a data processing agreement (DPA) with a supplier. It's worth understanding clearly what it does and doesn't mean, because it gets confused with two other things suppliers commonly point to: an SLA and a certification.

What TOMs actually means

Technical and organisational measures is the GDPR's own phrase for the safeguards a data processor puts in place to protect the personal data it handles. "Technical" covers the mechanisms themselves, things like access controls, encryption of data at rest and in transit, logging, and network segmentation. "Organisational" covers the human and procedural side, staff training, defined roles and responsibilities, incident response procedures, and how access to data is granted and reviewed. Together, they're meant to describe, concretely, how a processor actually protects the data it's trusted with, not just that it has a policy saying it does.

In practice, a provider's TOMs are usually written down as a specific document, or a specific section of a data processing agreement, that a customer can read and assess. That's the whole point of the concept: it gives a customer something concrete to evaluate, rather than a general assurance.

What's typically documented

Exactly what appears in a TOMs document varies by provider and by the data being processed, but common categories include:

  • Access control: who can reach personal data, how access is granted, and how it's reviewed or revoked.
  • Encryption: whether and how data is encrypted at rest and in transit.
  • Staff training and confidentiality: how employees who might handle personal data are trained and bound to confidentiality.
  • Incident response: how a data breach or security incident is detected, escalated, and reported.
  • Physical security: controls over the physical environment where data-processing infrastructure lives.
  • Backup and resilience: how data is protected against loss, separate from how it's protected against unauthorised access.

TOMs vs. an SLA

An SLA (service level agreement) is a commitment about service performance, typically availability or support response. TOMs is a different kind of document entirely: it's specifically about how personal data is protected, and it belongs to the compliance and legal side of a relationship rather than the performance side. A provider can meet every figure in its SLA and still have weak TOMs, or the reverse, they answer different questions. If you're assessing a supplier for GDPR purposes, the SLA tells you almost nothing about whether their data protection practices meet your requirements, that's what the TOMs document is for.

TOMs vs. a certification

A certification is proof, audited by an independent third party, that a provider meets a specific named standard. TOMs, by contrast, is typically the provider's own documented description of its practices, it may or may not have been independently audited. That doesn't make TOMs less useful, a detailed, specific TOMs document is often exactly what a DPA requires, but it's a different kind of evidence than a certification. When you're evaluating a provider, it's worth being clear on which one you're actually looking at: a provider's own account of its practices, versus a third party's confirmation that those practices meet a defined standard.

Related articles

  • Data sovereignty: why it matters and what EU datacenters change
  • Value Added Tax (VAT) treatment
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure