(3)
(4)
(5)
60.
(1)
(2)
(3)
(4)
(5)
61.
(1)
(2)
(3)
(4)
62.
Where the Commission is of the opinion that the intended processing does not comply
with this Proclamation, it shall prohibit the intended processing and make appropriate
proposals to remedy such non-compliance.
The Commission shall make public a list of the processing operations which are subject
to prior consultation in accordance with sub-Article (2) lit. (b) of this Article.
The data controller or data processor shall provide the Commission with the data
protection impact assessment and, whenever requested, any other information.
Data Protection by Design and by Default
The data controller, where applicable, the data processor shall both at the time of the
determination of the means for processing and at the time of the processing itself,
implement appropriate technical and organizational measures designed to:
(a) implement the personal data processing principles set out in this Proclamation in
an effective manner; and
(b) integrate the necessary safeguards into the processing in order to meet the
requirements of this Proclamation and protect the rights of data subjects.
The measures stipulated under sub-Article (1) of this Article shall take into
consideration the state of the art, the nature, scope, context and purposes of processing
as well as the risks of varying likelihood and severity for rights and freedoms of
individuals posed by the processing.
The data controller shall implement the appropriate technical and organizational
measures for ensuring that, by default, only personal data which are necessary for each
specific purpose of the processing is processed.
Sub-Article (3) of this Article applies to the amount of personal data collected, the extent
of processing of the personal data, the period of storage of the personal data and the
accessibility to the personal data.
The technical and organizational measures referred to in sub-Article (1) of this Article
shall ensure that personal data is not, by default, made accessible without the
individual's intervention to an indefinite number of individuals.
Duty to Destroy Personal Data
Unless the contrary is stipulated under Article 24 of this Proclamation, where the
purpose for storing personal data has lapsed, every data controller shall destroy or
delete the personal data as soon as is reasonably practicable.
The destruction or deletion of a record of personal data shall be done in a manner that
prevents its reconstruction in an intelligible form.
The data controller shall have the duty to notify any data processor holding the data of
its obligation under this Article.
Any data processor who receives a notification under sub-Article (3) of this Article shall,
as soon as is reasonably practicable, destroy the data specified by the data controller.
Joint Data Controllers
27