Data Security
and Risk Management

Under Art. 32 GDPR, the protection of personal data requires appropriate technical and organisational measures (“TOM”). A well-founded risk assessment and, where necessary, a Data Protection Impact Assessment (“DPIA”) help to identify and implement suitable protective measures.
You are here:

Legal background

According to Art. 32 GDPR, controllers must implement appropriate technical and organisational measures (“TOMs”) to ensure a level of security appropriate to the risk. The choice of TOMs is made taking into account the state of the art, the costs, and the risks of processing. For processing likely to result in a high risk, a Data Protection Impact Assessment (“DPIA”) must be carried out in accordance with Art. 35 GDPR.

Our support for you

As your external DPO, we advise you on how to define and maintain a level of security appropriate to the risk.

We support you in assessing the adequacy of your technical and organisational measures and advise you on their optimisation so that you can effectively counter risks to personal data.

For new processing projects, we advise you on conducting risk assessments and guide you through the process of carrying out Data Protection Impact Assessments, from the methodology to advising on the derivation of risk-mitigating measures.
Dr Marc Störing
Managing Director
Certified Information Privacy Professional, CIPP/E
+49 175 930 555 1
marc.stoering@osborneclarke-services.com
Dr. Marc Störing
Geschäftsführer
+49 175 930 555 1
marc.stoering@osborneclarke-services.com
Questions on managing privacy risks?
OC Services GmbH, Innere Kanalstraße 15, 50823 Cologne, Germany
Registration Court: Local Court of Cologne, HRB 92393
Managing Director: Gereon Abendroth, Nicolas Gabrysch-Wolff, Dr Marc Störing
Language: