20 security of personal data Data Protection No. 3 (c) advise the data controller or data processor on data protection impact assessments; and (d) act as the contact point for the authority and the data controller or data processor, on compliance matters under this act. Part VI—Data securIty 35.__(1) a data controller and data processor shall, taking into account— (a) the cost of technology; (b) the nature, scope, context and purpose of processing personal data; (c) the degree and likelihood of harm to a data subject that could result from the loss, disclosure or other misuse of personal data; and (d) the retention period of personal data, implement appropriate technical and organizational measures to ensure the security of personal data under the control or possession of the data controller or data processor. (2) notwithstanding the generality of subsection (1), a data controller and data processor shall implement the following measures to ensure the security of personal data— (a) pseudonymization or any other method of de-identification of personal data; (b) encryption of personal data; (c) develop and implement procedures to restore availability and access to personal data in a timely manner in the event of a physical or technical incident; (d) conduct periodic risk assessment of the data processing system and service including, without limitation, where the processing involves the transmission of personal data over an electronic communication network; (e) conduct regular testing, assessment and evaluation of the effectiveness of the measures implemented under this section and section 30 against current and evolving risks; and (f) carry out regular updates of the measures implemented under this section and introduce new measures to address any shortcomings in effectiveness identified and address evolving risks.

اختر الفقرة المستهدفة3