TOM
Overview of Technical and Organisational Measures (TOM)
This document provides an overview of the technical and organisational measures (TOM) that ixicare has implemented to protect personal data in accordance with the GDPR.
|
Domain |
Measures |
Purpose |
|
1. Data transfer |
|
Confidentiality and integrity of data during transfer |
|
2. Data storage |
|
Protection of stored data and full traceability |
|
3. Access management & authentication |
|
Access restriction, abuse prevention and accountability |
|
4. Data deletion & retention |
|
Compliance with retention policy and secure deletion of personal data |
|
5. Network & Device Security |
|
Protection against unauthorised access and cyber threats |
|
6. Availability & Continuity |
|
Uninterrupted service and recovery in the event of incidents |
|
7. Security monitoring & Change Management |
|
Early detection and mitigation of security risks |
|
8. Legal & Compliance |
|
Governance, compliance and chain responsibility |
|
9. Employees & Awareness |
|
Promotion of awareness and compliance by employees |
|
10. Incident & Data breach management |
|
Rapid response, transparency and recovery in the event of data breaches |
|
11. Rights of data subjects |
|
Strengthening the rights of data subjects and GDPR compliance |
|
12. Data minimisation & R&D |
|
Minimising data processing and secure use for innovation |