According to Art. 32 GDPR, controllers must implement appropriate technical and organisational measures (“TOMs”) to ensure a level of security appropriate to the risk. The choice of TOMs is made taking into account the state of the art, the costs, and the risks of processing. For processing likely to result in a high risk, a Data Protection Impact Assessment (“DPIA”) must be carried out in accordance with Art. 35 GDPR.