CyberSec Update #29: Assessing TOM Effectiveness | KWKR
The Effectiveness of TOMs Must Be Assessed Regularly and Based on a Procedure
In one of its recent personal data protection judgments (judgment of 7 May 2026, case no. III OSK 2694/23), the Polish Supreme Administrative Court upheld the position of the President of the Personal Data Protection Office (UODO), who imposed an administrative fine on an entrepreneur for failing to implement appropriate measures for the protection of personal data.
The ruling serves as another reminder that implementing security measures alone is not sufficient. Organizations must also ensure that such measures are regularly reviewed and tested for effectiveness.
What Should Your Procedure Include?
According to the President of UODO, the sanctioned organization failed to implement procedures for the regular testing, measuring and evaluation of the effectiveness of the technical and organizational measures designed to ensure the security of processing operations.
Technical and Organizational Measures (TOMs) are implemented by organizations to protect data and mitigate risk in accordance with GDPR requirements. However, deploying TOMs is only part of the process. Organizations should also establish procedures defining how, when and how often these measures will be assessed.
If You Do Not Test and Measure TOMs, You Increase the Risk of a Breach
The sanctioned organization had implemented numerous policies and procedures describing its data processing activities and submitted them to the supervisory authority during the inspection.
However, according to the President of UODO, those documents did not regulate the regular measurement and testing of the security measures already in place. This deficiency contributed to the occurrence of a personal data breach.
The case demonstrates that even extensive documentation may prove insufficient if an organization does not periodically verify whether its safeguards remain effective.
Testing Only When a Threat Emerges Is Not Enough
Conducting tests only when a threat arises, without implementing a procedure that specifies a schedule and frequency of testing activities, is insufficient.
The lack of regular testing prevented the sanctioned organization from identifying existing vulnerabilities within its system, despite having implemented various technical and organizational measures.
From a compliance perspective, organizations should adopt a proactive rather than reactive approach to security controls and their effectiveness.
Established Case Law
The Supreme Administrative Court’s judgment is not a groundbreaking development. For years, administrative courts have consistently emphasized the importance of risk assessments and ongoing analysis of personal data processing activities carried out by data controllers.
As a result, organizations should view security as a continuous process that includes both the implementation and periodic evaluation of safeguards.
The Legislator Does Not Provide a List of Specific Measures
The measures and procedures implemented by an organization should be appropriate to the identified level of risk. Consequently, the GDPR does not provide a predefined list of safeguards that every controller must adopt.
Instead, it is the controller’s responsibility to select appropriate security measures based on a prior assessment of threats and vulnerabilities. The outcome of this process should be the implementation of technical and organizational measures that adequately address the assessed risk.
Importantly, the obligation does not end with deployment. Organizations should continuously monitor and verify whether the selected measures remain effective over time.
How Can UODO’s Findings Be Applied to Information Security Management Systems?
Personal data protection and cybersecurity are closely interconnected. In modern organizations, it is difficult to achieve compliance with data protection requirements without maintaining an adequate level of information security.
A critical or important entity implementing an Information Security Management System (ISMS) should ensure that appropriate and proportionate technical and organizational measures are adopted in line with the assessed risk. Information system testing is also an essential element of the proper operation and maintenance of such systems.
The conclusions arising from the President of UODO’s decision should therefore be applied beyond personal data protection and extended to the broader cybersecurity environment.
Organizations should regularly test and measure the effectiveness of their security controls on the basis of procedures that ensure consistency and continuity. By conducting tests only when a threat materializes, an organization fails to meet the expectations of supervisory authorities.
Key Takeaways
Regular testing, measurement and evaluation of Technical and Organizational Measures should form an integral part of both data protection compliance and information security management.
Organizations that focus solely on implementing security controls, while neglecting their periodic review and assessment, expose themselves to higher operational risk and potential regulatory consequences.
A well-designed procedure defining the scope, frequency and documentation of effectiveness assessments can significantly strengthen both GDPR compliance and cybersecurity resilience.




