Protection
TOMs and privacy by design: deriving safeguards from the risk
Technical and organisational measures must fit the processing context and remain effective across the entire lifecycle.
8 minute read · Content as of 21.07.2026
Controls are not a universal shopping list
Protection needs, likely scenarios, scale, technology and implementation costs all feed into the selection of appropriate measures. The decision must be traceable and must be reviewed again when things change.
Privacy-friendly defaults reduce operational risk
Access, visibility, logging, retention and export should already be limited in the design. Compliance then depends less on later manual corrections.
- Minimise data scope and default retention
- Manage roles and permissions with recertification
- Apply pseudonymisation and encryption on a risk basis
- Demonstrate effectiveness through tests and operational evidence
Sources used
- General Data Protection Regulation (EU) 2016/679 · EU · check the consolidated version
- Guidelines for Controllers and Processors · EDPB
- ISO/IEC 27701:2025 – Privacy Information Management · ISO · 2025
- Privacy management, RoPA, DPIA and incident templates · KaitoSec