Technical and Organizational Measures (TOMs)

Version: 1.0
Effective Date: October 1, 2025

This document describes the technical and organizational measures implemented by HR Online Consulting LLC ("Processor") to ensure the security of Personal Data processed on behalf of customers ("Controllers") in accordance with Article 32 GDPR.


1. Information Security Governance

1.1 Responsibility

1.2 Policies and Training


2. Access Control

2.1 User Authentication

2.2 Role-Based Access Control (RBAC)


3. Data Access and Authorization

3.1 Logical Data Separation

3.2 Least Privilege Principle


4. Encryption and Data Security

4.1 Encryption in Transit

4.2 Encryption at Rest


5. Logging and Auditability

5.1 Audit Logs

5.2 Integrity


6. Data Integrity and Availability

6.1 Data Integrity

6.2 Backup and Recovery


7. Incident Management

7.1 Incident Detection

7.2 Incident Response

7.3 Breach Notification


8. Physical Security

8.1 Data Centers


9. Subprocessors

9.1 Use of Subprocessors

9.2 Oversight


10. Data Minimization and Retention

10.1 Data Minimization

10.2 Data Retention


11. Data Subject Rights Support


12. Continuous Improvement


13. Applicability

These TOMs apply to all Non-US customers and form an integral part of the Data Processing Agreement (DPA).