(c) to the measures taken for ensuring the reliability, integrity, and competence of
personnel having access to the personal data; and
(d) to the measures taken for ensuring the secure transfer of personal data.
(3) On behalf of a data controller, if a data processor carries out the processing of personal
data to protect it from the incidents identified in sub-section (1), the data controller
must ensure the data processor’s compliance with technical and international
standards of organisational security, as prescribed by the Commission.
(4) The data processor is independently liable to take steps to ensure compliance with
security standards prescribed under sub-section (1).
(5) Save as other related laws will also remain in the field of their respective domains.
10. Data retention requirements. –
(1) The personal data processed for any purpose shall not be kept longer than necessary
for the fulfillment of that purpose or as required under the law.
(2) It shall be the duty of a data controller to take all reasonable steps to ensure that all
personal data is destroyed or permanently deleted if it is no longer required for the
purpose for which it was to be processed or as required under sub-section (1).
11. Data integrity. A data controller shall take adequate steps to ensure that the required personal data is
accurate, complete, not misleading, and kept up to date concerning any direct or
indirect purpose for which the personal data was collected and processed further.
12. Record to be kept by the data controller. –
(1) A data controller shall keep and maintain a record of each application, notice, request,
or any other information concerning the personal data that has been or is processed
by him.
(2) The Commission may determine the manner and form in which the record is to be
maintained.
(3) The data controller shall apprise the Commission regularly about the type of data they
are collecting, and the processing undertaken on the collective data, as required under
16