6. The Requirement of Data Protection
Section 7
(1) The controller must plan and execute control operations in a way that these ensure the protection
of the private sphere throughout the application of the present Act and other regulations applicable
in connection with data control.
(2) The controller, as well as the data processor within their respective scope of activities, is obliged
to ensure data security, institute technical and organisational measures and develop procedural rules
required to enforce the present Act, as well as other data protection and confidentiality rules.
(3) Through the institution of the appropriate measures the data must be particularly protected from
unauthorised access, modification, transfer, disclosure, deletion or destruction, accidental
destruction and damage as well as disabled access occurring due to changes to the technology
applied.
(4) In order to protect data sets controlled electronically in various files it is necessary to ensure that
– unless otherwise permitted by law - data stored in files cannot be directly connected and linked to
the data subject by ensuring the appropriate technological solutions.
(5) During the course of the automated processing of personal data, the controller and data
processor ensures the following by taking additional measures:
a. prevents unauthorised data entry;
b. prevents the use of automatic data processing systems by unauthorised persons by using data
transfer devices;
c. ensures the ability to control and determine which bodies the personal data have or can be
sent to by using a data transfer device;
d. ensures the ability to control and determine which personal data has been registered in the
automatic data processing systems, when this was done and who did it;
e. ensures the ability to restore the systems installed in the event of malfunctions and;
f. compiles a report on errors occurring during the course of automated processing.
a. The controller and data processor must take account of the current level of
development of the relevant technology when determining and applying measures
taken to protect the data. The solution which ensures a higher level protection of the
personal data must be selected from among several possible control solutions, unless
this proves far too difficult for the controller.
7. Data Transfer to Other Countries
Section 8
(1) Data processors under the scope of the present Act are authorised to transfer personal data to
controllers or data processors undertaking data control in third countries should
a. the data subject have provided their explicit consent, or
b. conditions set out under Section 5 and Section 6 have been fulfilled and the adequate level
protection of the personal data have been ensured in the third country during the course of
the control and processing of the data transferred.
(2) Adequate level control of the personal data is ensured should
a. this be stated in a binding legal act of the European Union, or
b. an international treaty specifically containing the enforcement of rights specified under
Section 14 and the assurance of legal redress for the data subject, as well as rules
guaranteeing the independent control of the control and data processing procedure
concluded between the third country and Hungary be in effect.
(3) Personal data may be transferred to third countries to execute an international agreement to