Personal Data Protection Act
GN. NO. 395B (Contd)
(e) the data controller believes on reasonable
grounds that use of the personal data for that
other purpose is necessary to prevent or
lessen a serious and imminent threat to the
life or health of the data subject or other
person, or to public health or safety; or
(f) use of personal data for that other purpose is
necessary for compliance with the laws.
Limitations on
disclosure of
personal data
26. Where data controller holds personal data, he
shall not disclose the personal data to a person, other
than the data subject except in the circumstances
specified under section 25.
Security of
personal data
27.-(1) A data controller and his representatives
shall ensure that personal data is protected, by such
security safeguards that is reasonable in the
circumstances necessary for the personal data protection
against negligent loss or unauthorised destruction,
alteration, access or processing of the personal data.
(2) Security measures taken in accordance with
subsection (1) shall ensure an appropriate level of
security taking into account(a) the state of technological advancement and
the cost of implementing the measures; and
(b) the nature of the personal data to be protected
and the potential risks to the data subject.
(3) The data controller and data processor, as the
case may be, shall appoint a data protection officer who
shall ensure that the control and security measures are in
place to protect the personal data collected or being
processed.
(4) Implementation of activities of the data
processor shall be governed by a contract which
associates the data processor to the data controller to the
effect that the data processor acts under instructions of
the data controller and that the data processor is
additionally, responsible for ensuring compliance of the
17