(z) “personal data” means any information that relates directly or indirectly to a data subject, who is identified or identifiable from that information or other information in the possession of a data controller and/or data processor, including any sensitive or critical personal data. Provided that anonymized, or pseudonymized data which is incapable of identifying an individual is not personal data; (aa) “personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed; (bb) “prescribed” means as prescribed by Rules made under the provisions of this Act; (cc) “processing” means any operation or set of operations which is performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; (dd) “profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to the data subject in particular to analyse or predict aspects concerning that data subject’s attributes related to employment, social preferences, religious beliefs, economic situation, health, reliability, behaviour, location or movements; (ee) “pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person; 9

Select target paragraph3