SilentChat

DPA ANNEX · ART. 32 GDPR

Technical and organisational measures.

Effective: 21 August 2026

What this page is for: Art. 32 GDPR requires the processor to apply measures appropriate to the risk — and the controller to satisfy themselves that this is so. This page is the annex that lets you do that. It lists what is in place and, at the end, states explicitly what is not. A list of measures that only shows what exists is worthless for a risk assessment.
1
Physical access control
2
System access control
3
Data access control
4
Transmission control
5
Input control
6
Availability control
7
Separation control
8
Measures specific to AI processing
9
Resilience and restorability
10
Review and improvement
11
What is NOT in place
12
Questions about this annex
Technical and organisational measures (TOM) | SilentChat